ci/woodpecker/pr/ci Pipeline failed
Addresses both blockers from review 127 (rev-security-02) and corrects the severity claim in the original report. Blocker 1 -- mixed principals. Routing the comment through the token- authenticated gitea_issue_comment_api() attributed the comment to the token holder while the close still used --login $GITEA_LOGIN_NAME: two principals for one operation. `tea comment` accepts the same --repo/--login flags, so the tea branch now uses it and both calls carry the same principal. The no-login branch keeps the API helper for both, also a single principal. Blocker 2 -- no regression test. Adds test-issue-close-fail-closed.sh on the existing mocked-tea/sandboxed-git harness pattern. Asserts: a failed comment does not close the issue and exits non-zero; a successful comment does close it; the subcommand is top-level `tea comment`, never `tea issue comment`; and the comment and close carry the same --login. GREEN on this branch, RED on main. Severity correction. The original report said the issue closes anyway and the audit trail is silently lost. It does not: set -e at line 5 aborts the script when the comment fails, so the close is never reached. The real defect is that issue-close.sh -c cannot succeed at all where a tea login resolves -- loud, not silent. The explicit || guard is retained deliberately: a fail-closed property that depends on set -e disappears the moment anyone adds `|| true` or wraps the call in a conditional. Posted as a comment on #1081 and #1085. Refs #1081 Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Amf1Neca162odgcbCWMk1y