Repository navigation
Expand file tree
/
Copy pathaction.yml
More file actions
82 lines (76 loc) · 2.85 KB
/
Copy pathaction.yml
File metadata and controls
82 lines (76 loc) · 2.85 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
name: 'Authorization Check'
description: 'Check user authorization and determine approval environment'
inputs:
skip-check:
description: 'Skip collaborator check (for workflow_dispatch events)'
required: false
default: 'false'
username:
description: 'Username to check'
required: true
allowed-roles:
description: 'Comma-separated list of allowed roles (e.g., "triage,write,admin")'
required: true
issue-id:
description: 'Issue or PR number the command targets (defaults to the comment/PR from the event)'
required: false
default: ''
outputs:
approval-env:
description: 'Approval environment name (auto-approve or manual-approval)'
value: ${{ steps.collab-check.outputs.result || steps.auto-approve.outputs.result }}
head-sha:
description: 'PR head SHA resolved once in the authorization job so downstream acts on the same commit; empty for non-PR targets'
value: ${{ steps.pin.outputs.head-sha }}
head-repo:
description: 'PR head repository (owner/name), for fork checkouts'
value: ${{ steps.pin.outputs.head-repo }}
head-ref:
description: 'PR head branch name'
value: ${{ steps.pin.outputs.head-ref }}
runs:
using: 'composite'
steps:
- name: Checkout action
uses: actions/checkout@v6
with:
repository: strands-agents/devtools
ref: main
path: _authorization-check
sparse-checkout: |
authorization-check/scripts
- name: Collaborator Check
if: inputs.skip-check != 'true'
uses: actions/github-script@v8
id: collab-check
with:
result-encoding: string
script: |
const checkAuthorization = require('./_authorization-check/authorization-check/scripts/check-authorization.cjs');
return await checkAuthorization(context, github, {
username: '${{ inputs.username }}',
allowedRoles: '${{ inputs.allowed-roles }}'
});
- name: Auto-approve
if: inputs.skip-check == 'true'
id: auto-approve
uses: actions/github-script@v8
with:
result-encoding: string
script: |
return "auto-approve"
# Resolve the PR head once so the downstream jobs all act on the same
# commit, and for a /strands comment, stop if the head moved after the
# command was issued. No-op for non-PR targets.
- name: Pin and verify head commit
id: pin
uses: actions/github-script@v8
with:
script: |
const pinAndVerify = require('./_authorization-check/authorization-check/scripts/pin-and-verify.cjs');
const result = await pinAndVerify(context, github, { issueId: '${{ inputs.issue-id }}' });
if (result) {
core.setOutput('head-sha', result.headSha);
core.setOutput('head-repo', result.headRepo);
core.setOutput('head-ref', result.headRef);
}