Skip to content

test(bundle): drive checkOrgMember's missing payload.repository guard (auth.ts:43-45) through dist/index.js - #447

Open
hivecommons-hive[bot] wants to merge 1 commit into
mainfrom
quality/test-org-member-repository-guard
Open

hivecommons-hive[bot] wants to merge 1 commit into
mainfrom
quality/test-org-member-repository-guard

Conversation

@hivecommons-hive

Copy link
Copy Markdown
Contributor

Test Improvement

Adds __tests__/bundle/orgMemberRepositoryGuard.test.ts: two issue_comment /assign runs through dist/index.js whose payload has no repository object, the only way to reach checkOrgMember's guard at src/utils/auth.ts:43-45.

  • a collaborator is still assigned: the org-membership read is skipped (checkOrgMember error: context payload repository undefined is logged, no GET /orgs/…), context.repo falls back to GITHUB_REPOSITORY, and the collaborator read, comment read and assignee write follow in order
  • a stranger fails with no authorized users found after the same two reads and no write

Under npm run test:coverage:e2e the arm goes from 0 to 2 hits. Test-only change; dist/ is untouched (npm run build && npm run pack leaves it clean), lint passes.

Related Issue

Closes #446


Filed by quality agent (hold-gated mode). Human review required.

— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

… (auth.ts:43-45) through dist/index.js

Two issue_comment /assign runs whose payload has no repository object:
a collaborator is still assigned (the org read is skipped, context.repo
falls back to GITHUB_REPOSITORY) and a stranger fails with no authorized
users. Both assert the guard's debug line and that no /orgs/ read is made.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: quality <quality@hive.kubestellar.io>
@hivecommons-hive
hivecommons-hive Bot requested a review from jpmcb as a code owner October 10, 2026 20:45
@hivecommons-hive hivecommons-hive Bot added the hold Indicates that a PR should not merge because someone has issued a /hold command. label Oct 10, 2026
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

Important

Held for human review by the hive's ACMM level gate.

This PR was opened by the "quality" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the outreach agent is always held because it publishes project-facing communication.

Hive will keep the hold label until a human removes it. Operators can make a deliberate one-off release during an ACMM level change with release_level_holds=true, but level changes never release this hold automatically.

@github-actions

Copy link
Copy Markdown
Contributor

Please add a kind label with /kind failing-test or /kind cleanup.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hold Indicates that a PR should not merge because someone has issued a /hold command. needs-kind

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[quality] checkOrgMember's missing payload.repository guard (auth.ts:43-45) is reached by no bundle test

0 participants