Repository navigation
Gate PR previews with OWNERS and add direct review comments - #13
Merged
Merged
Conversation
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Make preview links visible directly in PR conversations and require authorization before publishing PR JavaScript on the dashboard's origin.
OWNERSinitially containsjonaburandspyysalo. Their PRs deploy automatically after checks pass. For other authors, the bot explains why deployment is blocked and provides a complete, copyable/deploy <40-character-commit-sha>command. Only a command from a current OWNER approving that exact commit grants access; later pushes require new approval. The publisher reads OWNERS from its trusted default-branch checkout, so a PR cannot authorize itself. Approval comments are checked on every reconciliation, including after coalesced workflow events. A rocket reaction acknowledges a deployed approval. Reactions alone do not authorize deployment.The bot creates one comment per PR with Open preview, the built commit, or approval instructions. It updates its own marked comment and leaves unchanged text and human comments alone. A previously approved preview remains available while a new commit awaits approval or passing checks. Revoked previews are removed on reconciliation. Closing a PR marks its existing comment Preview closed after the page is removed, with cleanup retained across deployment/reporting retries.
Ordinary comments never enter the deployment queue. Only the trusted publisher receives
pull-requests: write; PR builds retain read-only access. This gate authorizes browser code—it does not sandbox it. Previews still share the main dashboard's origin.Validation:
python3 -m tests.checkpasses, including the public browser suite.actionlintpasses for both workflows.