slawekjaranowski commented on code in PR #330:
URL:
https://github.com/apache/maven-gh-actions-shared/pull/330#discussion_r4179215062
##########
.github/workflows/pr-check.yml:
##########
@@ -78,6 +71,10 @@ jobs:
return;
}
+ // Values used by the job condition, logged for diagnosis
+ const { user, author_association } = context.payload.pull_request;
+ core.info(`Author: ${user.login}, type: ${user.type},
author_association: ${author_association}`);
Review Comment:
`context.payload.pull_request` is available in the called workflow –
`prNumber` is read from it and the job's `if:` works (e.g. the check was
skipped for a public member in apache/maven run 37223706079). The `TypeError`
came from the `Debug context` step, which used `github.event` – in
`github-script` `github` is the Octokit client, so `github.event` is undefined.
That step is removed here. The log intentionally uses the event payload, so it
shows the same values the job's `if:` evaluated.
##########
.github/workflows/pr-check.yml:
##########
@@ -92,6 +89,17 @@ jobs:
const { data: pr } = await github.rest.pulls.get({ owner, repo,
pull_number: prNumber });
const hasDeclaration = regex.test(pr.body || '');
Review Comment:
Comment wording applied. The permission check is already before fetching
comments, but I'd keep it without an early return – otherwise a comment added
before the fix (e.g. on apache/maven#13334) would never be hidden for a
committer.
##########
.github/workflows/pr-check.yml:
##########
@@ -92,6 +89,17 @@ jobs:
const { data: pr } = await github.rest.pulls.get({ owner, repo,
pull_number: prNumber });
const hasDeclaration = regex.test(pr.body || '');
+ // Committers don't need the declaration - checked here, as
private org members are not MEMBER in the event payload
+ let hasWriteAccess = false;
+ try {
+ const { data: perm } = await
github.rest.repos.getCollaboratorPermissionLevel({
+ owner, repo, username: pr.user.login,
+ });
Review Comment:
Added a note about the fallback. The permission endpoint needs only
`metadata: read`, which every `GITHUB_TOKEN` has, so no `members:read` is
required.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]