Skip to content

Fix claude-code-review.yml trust gate: check PR author, not head repo owner - #26

Open
jnasbyupgrade wants to merge 1 commit into
Postgres-Extensions:masterfrom
jnasbyupgrade:fix-claude-review-trust-gate
Open

Fix claude-code-review.yml trust gate: check PR author, not head repo owner#26
jnasbyupgrade wants to merge 1 commit into
Postgres-Extensions:masterfrom
jnasbyupgrade:fix-claude-review-trust-gate

Conversation

@jnasbyupgrade

Copy link
Copy Markdown
Contributor

The claude-review job's trust gate checked:

github.event.pull_request.head.repo.owner.login == 'jnasbyupgrade'

head.repo.owner.login only identifies "who owns the fork" for fork-headed PRs. For an upstream-branch-headed PR (base and head both in this repo -- required by gh stack, and also just what you get from gh pr create without a fork), head.repo.owner.login is always the repo's own org, never the actual PR author -- so the gate silently skipped review on every such PR regardless of who opened it.

Fix: check the PR author instead:

github.event.pull_request.user.login == 'jnasbyupgrade'

PR author can't be spoofed by a third party any more than head repo owner can, and it's the more direct question for this gate's actual purpose (trusting the PERSON asking for review, not the repository their branch happens to live in). Works for both fork-headed and upstream-branch-headed PRs.

… owner

head.repo.owner.login only identifies who owns the fork on fork-headed PRs.
For an upstream-branch-headed PR (base and head both in this repo -- e.g.
from gh stack, or gh pr create without a fork), it's always this repo's own
org, never the actual author, so the gate silently skipped review on every
such PR regardless of who opened it. Check pull_request.user.login instead,
which identifies the actual PR author in both cases.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: b67982e8-a235-46d0-a016-41c73d31eb1a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant