Repository navigation
docs(evi): align authorization note with the shipped principal gate - #783
Merged
Merged
Conversation
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
4 Skipped Deployments
|
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
|
Thank you for following the naming conventions! 🙏 |
@evlog/cli
evlog
@evlog/nuxthub
@evlog/signals
@evlog/telemetry
commit: |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Content pass: docs
Scanner ranked 155 files, 0 fixed mechanically, 1 reviewed, 1 changed.
Fixed mechanically
None.
apps/evi/docs/authorization.md
Score 95 → 95 (the sole candidate, T-14 on the "Why admin is not simply allowed everything" section, was judged lawful by the reviewer and left untouched). Verdict: pass after rewrite.
The page claimed an authorization state that no longer matches the source. Three critical factual corrections:
apps/evi/agent/channels/github.tsoverridesprincipalIdwithAUTONOMOUS_GITHUB_PRINCIPAL(github:evlogai,principalType: 'service');onPullRequest/onCheckSuiteare not wired and carry the same requirement when they land.onIssuewas wired.onIssueis wired, andwritePolicy(agent/lib/github/label-approval.ts) denies autonomous turns outright on every write outside label and triage work, so nothing parks.isMaintainergate intrust.ts, the per-toolrequireApprovalmap inextensions/github.ts,writePolicy) versus the tier attribute that remains a design, so the closing premise no longer contradicts the shipped state.Standard corrections: "every write tool ships behind the SDK's
always()approval" corrected to per-tool predicates withcloseIssueandcreatePullRequestReviewnamed as the two omissions; the unsourced "roughly 7k tokens per turn" figure dropped;git__pushscope corrected tocanAccessAdminTools(maintainers plus schedule sessions, withmain/masterrefused for every caller); "nothing binds the reply to the person who triggered the turn" replaced with the shipped upstream mechanism, eve captures the requester's auth on the pending request and exportsApprovalResponsePolicy, which this deployment does not configure.Not applied
None.
Reported, not changed
apps/evi/docs/authorization.md:160, dropped by the reviewer as the lawful twin (a conceptual passage framing a decision, carrying its mechanism in the text).Checks
node scripts/content-lint/index.mjs apps/evi/docs/authorization.mdon the saved file: score 95, 0 dashes, sole candidate T-14 (dropped as above). Command and result on revision1b8e758's content (digest0192c31d...), verified by a secondcontent_reviewpass against the source, verdict pass.vercel/eve@0.71.0(defaults.ts,approval/definition.ts, channel docs),vercel-labs/github-tools(build.ts), andapps/evi/agent/{channels/github.ts, extensions/github.ts, lib/trust.ts, lib/github/label-approval.ts}ata2cfcca.apps/*.pnpm run lint/typecheck/testnot run: markdown-only diff, nothing they cover.ELI5
The agent keeps an internal design note about who is allowed to make it write things on GitHub. The note still described an older plan: it said unattended bot turns would run under whoever filed the issue, and that nothing stops someone else from approving a request. The actual code had already moved past that: those turns run as the bot's own identity and get refused rather than stuck waiting. This PR updates the note to match the code and clearly separates what already exists from what is still just an idea.