The wrapper reconciles whichever Review the service returns without checking it is for this repository and branch #53
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The wrapper never compares the Review it gets back with the one it asked for. A Review of another repository or target branch would be posted to the pull request.
What happens
After the create call,
review()takes the returned Review's id and goes on to reconcile it (src/wrapper/orchestrator.ts:84-92). The bundled client checks that the response has the right shape, and a malformed Review ends the run before any write. Beyond that, the only comparison is the Review'sderivation.subject_commitagainst the head, and it only decides whether to log a line (src/wrapper/orchestrator.ts:93-98). Repository, scope kind, target branch and tree are never compared. No mismatch stops the run.Reproduced at
9f272a52with the committed bundle on Node 24.21.0 against a stand-in service. For a request aboutacme/widgets, a Review ofother/elsewhereon another forge host, with targetrelease/9and commit9999…, was reconciled on an event run (s5a-foreign-prt) and on a dispatch run (s5a-foreign-dispatch). Each wrote the summary comment and an inline review to the pull request.What it should do instead
Compare the Review's
repo.forge_host,repo.slug,scope_kindandderivation.target_refwith what the wrapper asked for (inputs.forgeHost,inputs.slug, adiffscope,inputs.baseBranch), and end the run before any write when one differs. A differentsubject_commitstays acceptable: an event run sendsattach_same_diff: true(src/wrapper/orchestrator.ts:90, added in #29), so the service may attach an earlier commit's Review.Why it matters
The service decides which Review a pull request receives, and the wrapper posts it under that pull request's name. A service bug or a compromised service could post another repository's findings, which may quote that repository's code, onto this pull request.
The service is a trusted party, pinned by
expected-service-origin. This is a guard against service faults, not against pull request authors, and the comparison is four fields.🤖 Generated with Claude Code