Split tokens #1

Merged
temeddix merged 2 commits from split-tokens into main 2026-09-13 14:15:24 +00:00
Owner

The agent and the bot are now two accounts, and the runner is one Deno script.

  • author-token (was gitea-token): commits, pushes, and opens pull requests; the agent sees it as GITEA_TOKEN, and commits use that account's login and email.
  • reviewer-token: posts comments and reviews as the bot; withheld from the agent's environment so it can never approve as the bot.
  • A pull_request run posts a review instead of a comment: REQUEST_CHANGES when the response mentions @bot, COMMENT when the run failed, APPROVED otherwise. Gitea refuses self-approval, so the two accounts must differ.
  • The reviewer checks the whole repository against commons/code-rules, which is fetched and embedded in the prompt, and requests changes for violations even when the diff did not cause them.
  • run.ts replaces the three shell scripts plus jq, envsubst, and ansifilter; only deno is added to the install step, per the rules' Deno-over-Node policy. A .gitea workflow runs deno fmt, lint, and check.

Callers must rename gitea-token and add reviewer-token (write:issue and write:repository scopes). A rejection stays until the bot reviews again, so callers that want it lifted after a fix should trigger on pull_request: [opened, synchronize].

Verified with a fake claude binary against this PR in an isolated HOME: git author configured from the token, prompt rendered with rules and comment history, events streamed, reviewer token absent from the agent's environment, review posted (then deleted).

The agent and the bot are now two accounts, and the runner is one Deno script. - `author-token` (was `gitea-token`): commits, pushes, and opens pull requests; the agent sees it as `GITEA_TOKEN`, and commits use that account's login and email. - `reviewer-token`: posts comments and reviews as the bot; withheld from the agent's environment so it can never approve as the bot. - A `pull_request` run posts a review instead of a comment: `REQUEST_CHANGES` when the response mentions `@bot`, `COMMENT` when the run failed, `APPROVED` otherwise. Gitea refuses self-approval, so the two accounts must differ. - The reviewer checks the whole repository against `commons/code-rules`, which is fetched and embedded in the prompt, and requests changes for violations even when the diff did not cause them. - `run.ts` replaces the three shell scripts plus `jq`, `envsubst`, and `ansifilter`; only `deno` is added to the install step, per the rules' Deno-over-Node policy. A `.gitea` workflow runs `deno fmt`, `lint`, and `check`. Callers must rename `gitea-token` and add `reviewer-token` (`write:issue` and `write:repository` scopes). A rejection stays until the bot reviews again, so callers that want it lifted after a fix should trigger on `pull_request: [opened, synchronize]`. Verified with a fake `claude` binary against this PR in an isolated `HOME`: git author configured from the token, prompt rendered with rules and comment history, events streamed, reviewer token absent from the agent's environment, review posted (then deleted).
temeddix added 1 commit 2026-09-13 13:58:45 +00:00
temeddix added 1 commit 2026-09-13 14:09:57 +00:00
Rewrite the runner in TypeScript
Check / deno (pull_request) Successful in 45s
e65ac772f6
temeddix merged commit 8c2041bbc5 into main 2026-09-13 14:15:24 +00:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: commons/bot-agents#1