diff --git a/packages/mosaic/framework/tools/git/issue-close.sh b/packages/mosaic/framework/tools/git/issue-close.sh index 646c8b09..05788e6d 100755 --- a/packages/mosaic/framework/tools/git/issue-close.sh +++ b/packages/mosaic/framework/tools/git/issue-close.sh @@ -91,13 +91,27 @@ elif [[ "$PLATFORM" == "gitea" ]]; then GITEA_LOGIN_NAME=$(get_gitea_login || true) if [[ -n "$GITEA_LOGIN_NAME" ]]; then if [[ -n "$COMMENT" ]]; then - tea issue comment "$ISSUE_NUMBER" "$COMMENT" --repo "$OWNER/$REPO" --login "$GITEA_LOGIN_NAME" + # `tea issue comment` is NOT a subcommand (tea 0.11.x lists only + # list/create/edit/reopen/close); comments are the top-level `tea comment`. + # The call therefore always failed, was unchecked, and the script proceeded + # to close the issue anyway -- losing the record of WHY it was closed. + # Route through the authenticated API helper: it is login-independent and is + # already the mechanism used by the no-login branch below. + gitea_issue_comment_api || { + echo "Error: failed to post comment on #$ISSUE_NUMBER -- NOT closing (fail closed)." >&2 + exit 1 + } fi tea issue close "$ISSUE_NUMBER" --repo "$OWNER/$REPO" --login "$GITEA_LOGIN_NAME" else echo "No tea login configured for $(get_remote_host); using authenticated Gitea API fallback." >&2 if [[ -n "$COMMENT" ]]; then - gitea_issue_comment_api + # Fail closed here too: an unchecked comment lets the issue close without its + # audit trail, which is the same defect as the tea path above. + gitea_issue_comment_api || { + echo "Error: failed to post comment on #$ISSUE_NUMBER -- NOT closing (fail closed)." >&2 + exit 1 + } fi gitea_issue_close_api fi