4 Commits

Author SHA1 Message Date
temeddix 6f782c35ef Wait for login instructions
Check / deno (pull_request) Successful in 33s
2026-09-14 17:05:09 +09:00
temeddix c637553b5f Skip empty login status comment
Check / deno (pull_request) Successful in 33s
2026-09-14 16:52:00 +09:00
temeddix 743c60e8a5 Recover invalid bot authentication
Check / deno (pull_request) Successful in 34s
2026-09-14 16:39:33 +09:00
temeddix 419439baf6 Make bot review setup self-contained
Check / deno (pull_request) Successful in 34s
2026-09-14 16:16:36 +09:00
5 changed files with 20 additions and 129 deletions
+1 -5
View File
@@ -14,8 +14,4 @@ jobs:
- uses: denoland/setup-deno@v2 - uses: denoland/setup-deno@v2
- run: >- - run: deno fmt --check . && deno lint . && deno check run.ts
deno fmt --check . &&
deno lint . &&
deno check run.ts &&
deno test
+18 -25
View File
@@ -19,31 +19,24 @@ author's push credentials. Read the code there, run its checks and tests when
they bear on the task, and push from there. they bear on the task, and push from there.
For a `pull_request` event, and for a comment on a pull request that asks you to For a `pull_request` event, and for a comment on a pull request that asks you to
review it, invoke the installed `superpowers:requesting-code-review` skill review it, review the PR without changing code against its base and head. Run
before inspecting the PR. You are the reviewer that has already been dispatched, the project's checks on the head and treat a failure as at least Important.
so run the skill's code reviewer template yourself instead of dispatching Check the whole repository against the code rules at the end of this prompt, not
another reviewer. Use the pull request and triggering instruction as its only the diff; a violation is at least Important even when the diff did not
description and requirements, and review the exact base and head SHAs without cause it. Write the complete review, and nothing else, to the file
changing code. Run the project's required checks on the head and treat a real `${REVIEW_PATH}`: it is posted verbatim as a pull request review from the bot
failure as at least Important. The bot automation workflow itself is not a account, and your final response is not posted at all. The file's first line
project check: ignore its skipped or canceled duplicate/automatic runs, and must be exactly the verdict and nothing else: `Approved` when the head is ready
never reject a PR because the current review run is unfinished. Only a failed to merge, `Changes requested` otherwise. The mark in front of it is added when
required check for the reviewed head blocks approval. Check the whole repository posting, so write the words alone; any other first line is posted as a plain
against the code rules at the end of this prompt, not only the diff; a violation comment, which wastes the run. Minor issues alone never block, and neither does
is at least Important even when the diff did not cause it. Write the complete a finding the author has answered in the comment history below as intended or a
review, and nothing else, to the file `${REVIEW_PATH}`: it is posted verbatim as false alarm, once the code or docs make that clear. When the verdict is
a pull request review from the bot account, and your final response is not `Changes requested`, the second line names what must change in one line,
posted at all. The file's first line must be exactly the verdict and nothing addressed to the author; the author's own agent picks the fixes up, so never ask
else: `Approved` when the head is ready to merge, `Changes requested` otherwise. `@bot` to make them. For UI changes, check that the result is aligned, clean,
The mark in front of it is added when posting, so write the words alone; any and pixel-perfect, and that included screenshots prove the intended result was
other first line is posted as a plain comment, which wastes the run. Minor achieved.
issues alone never block, and neither does a finding the author has answered in
the comment history below as intended or a false alarm, once the code or docs
make that clear. When the verdict is `Changes requested`, the second line names
what must change in one line, addressed to the author; the author's own agent
picks the fixes up, so never ask `@bot` to make them. For UI changes, check that
the result is aligned, clean, and pixel-perfect, and that included screenshots
prove the intended result was achieved.
Every finding that belongs to one line of the diff goes on that line instead of Every finding that belongs to one line of the diff goes on that line instead of
into the body. Write those to `${ANCHORS_PATH}` as a JSON array, each entry into the body. Write those to `${ANCHORS_PATH}` as a JSON array, each entry
+1 -17
View File
@@ -4,11 +4,6 @@
// so it appears as the bot account. // so it appears as the bot account.
import { TextLineStream } from "jsr:@std/streams@1/text-line-stream"; import { TextLineStream } from "jsr:@std/streams@1/text-line-stream";
import { retryInvalidToken } from "./auth.ts"; import { retryInvalidToken } from "./auth.ts";
import {
type BotType,
parseBotType,
superpowersInstallCommands,
} from "./superpowers.ts";
type GiteaUser = { login: string; email: string }; type GiteaUser = { login: string; email: string };
type GiteaComment = { user: GiteaUser; created_at: string; body: string }; type GiteaComment = { user: GiteaUser; created_at: string; body: string };
@@ -23,7 +18,6 @@ const API = env("GITEA_API_URL");
const REPO = env("GITEA_REPOSITORY"); const REPO = env("GITEA_REPOSITORY");
const INDEX = env("ISSUE_INDEX"); const INDEX = env("ISSUE_INDEX");
const EVENT = env("EVENT_NAME"); const EVENT = env("EVENT_NAME");
const BOT = parseBotType(env("BOT_TYPE"));
const AUTHOR_TOKEN = env("GITEA_TOKEN"); const AUTHOR_TOKEN = env("GITEA_TOKEN");
const REVIEWER_TOKEN = env("REVIEWER_TOKEN"); const REVIEWER_TOKEN = env("REVIEWER_TOKEN");
const RULES_PATH = "repos/commons/code-rules/raw/README.md"; const RULES_PATH = "repos/commons/code-rules/raw/README.md";
@@ -152,14 +146,6 @@ async function run(command: string, args: string[]): Promise<void> {
if (!success) throw new Error(`${command} ${args[0]} exited with ${code}`); if (!success) throw new Error(`${command} ${args[0]} exited with ${code}`);
} }
// The reviewer uses Superpowers' requesting-code-review template. Both plugin
// installers are idempotent on the persisted bot home.
async function installSuperpowers(bot: BotType): Promise<void> {
for (const { command, args } of superpowersInstallCommands(bot)) {
await run(command, args);
}
}
// Commits belong to the same account as the pull request they end up in. // Commits belong to the same account as the pull request they end up in.
async function configureGitAuthor(): Promise<void> { async function configureGitAuthor(): Promise<void> {
const user: GiteaUser = await (await gitea(AUTHOR_TOKEN, "user")).json(); const user: GiteaUser = await (await gitea(AUTHOR_TOKEN, "user")).json();
@@ -202,7 +188,6 @@ async function runClaude(prompt: string): Promise<string> {
"Run `claude setup-token` locally and set the `bot-token` action input.", "Run `claude setup-token` locally and set the `bot-token` action input.",
); );
} }
await installSuperpowers("claude");
const claude = new Deno.Command("claude", { const claude = new Deno.Command("claude", {
args: [ args: [
"--print", "--print",
@@ -272,7 +257,6 @@ async function runCodex(prompt: string): Promise<string> {
}) })
.output(); .output();
if (!loggedIn.success) await codexDeviceLogin(); if (!loggedIn.success) await codexDeviceLogin();
await installSuperpowers("codex");
const file = await Deno.makeTempFile(); const file = await Deno.makeTempFile();
const attempt = async () => { const attempt = async () => {
const codex = new Deno.Command("codex", { const codex = new Deno.Command("codex", {
@@ -310,7 +294,7 @@ async function runCodex(prompt: string): Promise<string> {
try { try {
await configureGitAuthor(); await configureGitAuthor();
const prompt = await renderPrompt(); const prompt = await renderPrompt();
const result = BOT === "claude" const result = env("BOT_TYPE") === "claude"
? await runClaude(prompt) ? await runClaude(prompt)
: await runCodex(prompt); : await runCodex(prompt);
await postResult(result); await postResult(result);
-42
View File
@@ -1,42 +0,0 @@
export type BotType = "claude" | "codex";
export type InstallCommand = {
command: string;
args: string[];
};
export function parseBotType(value: string): BotType {
if (value === "claude" || value === "codex") return value;
throw new Error(`unsupported bot type: ${value}`);
}
export function superpowersInstallCommands(
bot: BotType,
): InstallCommand[] {
if (bot === "claude") {
return [
{
command: "claude",
args: [
"plugin",
"marketplace",
"add",
"obra/superpowers-marketplace",
],
},
{
command: "claude",
args: [
"plugin",
"install",
"-y",
"superpowers@superpowers-marketplace",
],
},
];
}
return [{
command: "codex",
args: ["plugin", "add", "superpowers@openai-curated-remote"],
}];
}
-40
View File
@@ -1,40 +0,0 @@
import { assertEquals, assertThrows } from "jsr:@std/assert@1";
import { parseBotType, superpowersInstallCommands } from "./superpowers.ts";
Deno.test("installs Superpowers from the Codex marketplace", () => {
assertEquals(superpowersInstallCommands("codex"), [{
command: "codex",
args: ["plugin", "add", "superpowers@openai-curated-remote"],
}]);
});
Deno.test("installs Superpowers from the Claude marketplace", () => {
assertEquals(superpowersInstallCommands("claude"), [
{
command: "claude",
args: [
"plugin",
"marketplace",
"add",
"obra/superpowers-marketplace",
],
},
{
command: "claude",
args: [
"plugin",
"install",
"-y",
"superpowers@superpowers-marketplace",
],
},
]);
});
Deno.test("rejects an unsupported bot type", () => {
assertThrows(
() => parseBotType("other"),
Error,
"unsupported bot type: other",
);
});