Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 8 additions & 2 deletions standards/workflows/pr-review-mention.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,11 @@
#
# PR Review Mention — thin caller for the org-level reusable.
# To adopt: copy this file to .github/workflows/pr-review-mention.yml in your repo.
# Requires: GH_PAT_WORKFLOWS org secret (already present in petry-projects org).
# Requires (org secrets, already present in petry-projects org):
# GH_PAT_DON_PETRY canonical PAT for API calls and dispatching the review agent.
# GH_PAT_WORKFLOWS is the deprecated transition alias, kept as the
# `||` fallback until the persona rename lands fleet-wide.
# DON_PETRY_BOT_GH_PAT PAT owned by donpetry-bot, for posting acknowledgement comments.
name: PR Review — Mention Trigger

on:
Expand All @@ -38,4 +42,6 @@ jobs:
permissions:
pull-requests: write
uses: petry-projects/.github/.github/workflows/pr-review-mention-reusable.yml@pr-review-mention/stable # NOSONAR(githubactions:S7637) first-party channel ref
secrets: inherit
secrets:
GH_PAT_WORKFLOWS: ${{ secrets.GH_PAT_DON_PETRY || secrets.GH_PAT_WORKFLOWS }}
DON_PETRY_BOT_GH_PAT: ${{ secrets.DON_PETRY_BOT_GH_PAT }}
51 changes: 51 additions & 0 deletions test/workflows/pr-review-mention/stub-secrets.bats
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
#!/usr/bin/env bats
# Tests for the credential wiring of the canonical caller stub
# standards/workflows/pr-review-mention.yml (issue #791).
#
# The persona-identity rename (#1316 / .github-private#1317) renamed the
# workflows PAT org secret GH_PAT_WORKFLOWS -> GH_PAT_DON_PETRY, keeping the old
# name as a `||` transition fallback. The stub must source the reusable's
# GH_PAT_WORKFLOWS input from that fallback expression.
#
# Fail-closed contract: the reusable declares BOTH GH_PAT_WORKFLOWS and
# DON_PETRY_BOT_GH_PAT as `required: true`. An explicit `secrets:` block passes
# only the keys it lists (no implicit inherit), so the stub MUST still carry
# DON_PETRY_BOT_GH_PAT or the acknowledgement step loses its token. These tests
# pin both the rename and that retention.

load 'helpers/setup'

STUB="${TT_REPO_ROOT}/standards/workflows/pr-review-mention.yml"

# ── the rename: workflows PAT sourced from GH_PAT_DON_PETRY with old-name fallback

@test "stub: GH_PAT_WORKFLOWS input uses the GH_PAT_DON_PETRY || GH_PAT_WORKFLOWS fallback" {
run yq -r '.jobs.pr-review-mention.secrets.GH_PAT_WORKFLOWS' "$STUB"
[ "$status" -eq 0 ]
[ "$output" = '${{ secrets.GH_PAT_DON_PETRY || secrets.GH_PAT_WORKFLOWS }}' ]
}

# ── fail-closed: the bot-comment PAT must not silently drop out of the wiring ──

@test "stub: retains DON_PETRY_BOT_GH_PAT (required by the reusable's ack step)" {
run yq -r '.jobs.pr-review-mention.secrets.DON_PETRY_BOT_GH_PAT' "$STUB"
[ "$status" -eq 0 ]
[ "$output" = '${{ secrets.DON_PETRY_BOT_GH_PAT }}' ]
}

@test "stub: uses an explicit secrets mapping, not bare 'inherit'" {
# With `secrets: inherit`, .secrets is a scalar string; the explicit block is a
# mapping. An explicit block is what lets us rewire GH_PAT_WORKFLOWS per #791.
run yq -r '.jobs.pr-review-mention.secrets | tag' "$STUB"
[ "$status" -eq 0 ]
[ "$output" = '!!map' ]
}

# ── contract this stub depends on: both PATs are required by the reusable ──────

@test "reusable: declares GH_PAT_WORKFLOWS and DON_PETRY_BOT_GH_PAT as required" {
run yq -r '.on.workflow_call.secrets.GH_PAT_WORKFLOWS.required' "$TT_WORKFLOW"
[ "$output" = 'true' ]
run yq -r '.on.workflow_call.secrets.DON_PETRY_BOT_GH_PAT.required' "$TT_WORKFLOW"
[ "$output" = 'true' ]
}
Comment on lines +46 to +51

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

low

For consistency and robustness, we should assert that the yq command executed successfully ([ "$status" -eq 0 ]) before asserting on its output. This matches the pattern used in the other tests in this file.

@test "reusable: declares GH_PAT_WORKFLOWS and DON_PETRY_BOT_GH_PAT as required" {
  run yq -r '.on.workflow_call.secrets.GH_PAT_WORKFLOWS.required' "$TT_WORKFLOW"
  [ "$status" -eq 0 ]
  [ "$output" = 'true' ]
  run yq -r '.on.workflow_call.secrets.DON_PETRY_BOT_GH_PAT.required' "$TT_WORKFLOW"
  [ "$status" -eq 0 ]
  [ "$output" = 'true' ]
}

Comment thread
coderabbitai[bot] marked this conversation as resolved.
Loading