From a756ba5d3b0ceb044d2d7defcb51375f17012fa7 Mon Sep 17 00:00:00 2001 From: review Date: Fri, 18 Sep 2026 15:16:43 +0800 Subject: [PATCH] fix(codex-review): let maintainer-authorized fork PRs re-review on push MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The auto re-review added in #631 never worked for fork PRs. Our gate job correctly authorizes a re-review when the PR carries a maintainer assignee, but codex-action then runs its OWN write-access check against the triggering actor — which on a fork PR's `synchronize` is the PR author (read access). So every fork auto re-review failed with: Actor '' is not permitted to run this action ... Detected 'read'. Pass `allow-users: "*"` to disable codex-action's actor check. This does NOT widen who can trigger a review: our `gate` job is the real, stricter authorization door (an un-authorized PR never reaches this job at all), and codex-action's check is redundant with it while being wrong for the fork push case. All secret-protecting layers are unchanged: gate authorization, trusted base checkout, PR code read as diff data only (never built/installed/ run), persist-credentials: false, and Codex staying :read-only. --- .github/workflows/codex-review-on-assign.yml | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/.github/workflows/codex-review-on-assign.yml b/.github/workflows/codex-review-on-assign.yml index b6af364c9..30fe08a45 100644 --- a/.github/workflows/codex-review-on-assign.yml +++ b/.github/workflows/codex-review-on-assign.yml @@ -19,7 +19,10 @@ name: Codex Review on Assign # # 1. Maintainer gate: review only runs when a maintainer (write/admin/maintain) # authorized this PR — either the current assigner, or an existing assignee. -# A fork PR author's own pushes cannot start it. (The `gate` job.) +# A fork PR author's own pushes cannot start it. (The `gate` job.) This gate +# is THE authorization door; codex-action's own actor check is disabled with +# `allow-users: "*"` because it keys off the fork author and cannot see our +# maintainer authorization — see the note on that input below. # 2. The PR's code is treated as PASSIVE DATA only. We check out the trusted # BASE commit (never the PR head), and expose the PR changes to Codex solely # through `git diff` — which reads git objects, it does not execute them. @@ -131,6 +134,14 @@ jobs: uses: openai/codex-action@v1 with: openai-api-key: ${{ secrets.OPENAI_API_KEY }} + # Delegate the "who may run" decision to our own `gate` job above. + # codex-action's built-in check keys off the TRIGGERING ACTOR, which on + # a fork PR's `synchronize` is the PR author (read access) — so it would + # reject every auto re-review even though a maintainer authorized the PR. + # Our gate already enforces maintainer authorization (an un-authorized PR + # never reaches this job), so this check is redundant here; disabling it + # does NOT widen who can run — the gate remains the single, stricter door. + allow-users: "*" # Optional overrides. Leave the corresponding secret/variable unset to # use Codex's built-in defaults (both fall back safely when empty). responses-api-endpoint: ${{ secrets.OPENAI_RESPONSES_API_ENDPOINT }}