Skip to content

chore(issue): 强制非维护者通过 Issue 表单提交 (#990) - #1011

Merged
1lck merged 3 commits into
previewfrom
chore/990-enforce-issue-forms
Oct 1, 2026
Merged

1lck merged 3 commits into
previewfrom
chore/990-enforce-issue-forms

Conversation

@1lck

@1lck 1lck commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Closes #990

背景与行为

blank_issues_enabled: false 只隐藏网页空白 Issue 入口,不能阻止普通用户通过 API、CLI 或第三方客户端绕过表单。本 PR 给 Bug / Feature 表单添加来源标签,并在 Issue 创建或重新打开时检查:write / maintain / admin 作者放行;其他作者需要允许的来源标签,否则收到中英双语说明及表单链接,并以 not_planned 关闭。

改动明细

  • 两个 Issue Form 保留原有 bug / enhancement 标签,分别增加 issue-form:bug / issue-form:feature。
  • 新增纯函数判定模块,集中管理允许的表单、真实权限判断、来源标签、评论去重及双语文案;不以 author_association 推断协作者写权限。
  • 新增 issues: [opened, reopened] 门禁:作者自己重新打开仍需检查,其他触发者(例如维护者转移或重新打开)跳过;Bot 和 OWNER 跳过。
  • 权限读取失败、允许的标签缺失或归档、Issue 已关闭等情况保留 Issue。归档状态检查 getLabel 返回的 archived_at,不能只以接口成功作为可用依据。
  • 合并事件和当前标签,并在关闭前重新读取 Issue,降低标签延迟写入和维护者并发操作带来的误判;隐藏标记避免重复评论。
  • 分类工作流改用 addLabels / removeLabel,仅增删自己管理的类型、优先级、平台和模块标签,避免旧快照的 setLabels 覆盖稍后写入的来源标签或其他非托管标签。
  • 新增工作流编排回归测试,执行实际 github-script 脚本并模拟 API,确定性覆盖作者关闭后重开、维护者重开、归档标签、标签写入竞态、权限读取失败及维护者豁免。
  • 新增 Verify issue automation CI,对相关 PR 和 main/preview 推送运行 Issue 自动化测试,单测试超时 10 秒、job 超时 5 分钟;同步更新中文 Agent Note。

工作流使用 contents: read、issues: write,checkout 禁用凭据持久化;Issue 标题和正文不插入 shell 或表达式。测试 CI 只需要 contents: read。

验证

  • node --test --test-timeout=10000 scripts/test-lithe-issue-*.mjs:23 个测试全部通过,包括 7 个工作流编排测试;生成了本地逐测试计时 HTML / JUnit 报告。
  • actionlint:门禁、分类、新增测试工作流通过。
  • Agent Notes、测试稳定性、runtime bundle immutability、平台功能矩阵及变更门禁、diff 空白检查:通过。
  • 修复前已通过离线模拟复现“分类旧快照覆盖来源标签后门禁误关”;新增回归测试确认来源标签保留、Issue 不关闭。
  • 本 PR 无平台产品实现路径改动。未创建真实 GitHub 测试 Issue,端到端事件验证仍待部署后进行。

部署条件与限制

  1. 在仓库创建且保持未归档的 issue-form:bug、issue-form:feature 两个标签;任一不可用时门禁安全退化,不关闭无来源标签的 Issue。
  2. Issue 事件使用默认分支上的工作流;合入 preview 后,需同步到 main 才生效。
  3. 部署后使用非协作者账号分别验证两个表单、空白/API Issue 和作者重新打开,再确认维护者豁免。
  4. 重新读取不能从理论上排除 GitHub 极端延迟写入标签;没有进行真实事件端到端验证。历史 Issue 不会批量追溯,但作者重新打开时会进入检查。

- Bug / Feature 表单新增 issue-form:bug、issue-form:feature 来源标签
- 新增 lithe-issue-form-gate 工作流:issues opened 时校验作者权限,
  非 write/maintain/admin 作者且无表单标签时双语评论并关闭
- 判定逻辑抽到 .github/lithe-issue-form/logic.mjs,权限未知、表单标签
  未创建、转移等不确定情况一律不关闭
- 新增 scripts/test-lithe-issue-form-gate.mjs 覆盖验收标准
- 新增 process Agent Note 记录决策与备选方案

Co-Authored-By: Claude <noreply@anthropic.com>
@ghfind-review ghfind-review Bot added the review: high ghfind author score; see https://ghfind.com label Oct 1, 2026
表单标签可能在 Issue 创建后约 1 秒才写入(见 #987 的事件记录),
在评论和关闭前再读一次 Issue 并重新判定,出现表单标签或已被关闭时不处理。

Co-Authored-By: Claude <noreply@anthropic.com>

@xiaoyumuxi xiaoyumuxi left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

有两个会破坏“非维护者必须通过 Issue Form 提交”这一约束的边界问题,建议修复后再合并。

Comment thread .github/workflows/lithe-issue-form-gate.yml Outdated
Comment thread .github/workflows/lithe-issue-form-gate.yml Outdated
@1lck
1lck merged commit 7decc11 into preview Oct 1, 2026
17 checks passed
@1lck
1lck deleted the chore/990-enforce-issue-forms branch October 1, 2026 08:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

review: high ghfind author score; see https://ghfind.com

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants