Addresses both blockers from review 127 (rev-security-02) and corrects the severity claim in the original report. Blocker 1 -- mixed principals. Routing the comment through the token- authenticated gitea_issue_comment_api() attributed the comment to the token holder while the close still used --login $GITEA_LOGIN_NAME: two principals for one operation. `tea comment` accepts the same --repo/--login flags, so the tea branch now uses it and both calls carry the same principal. The no-login branch keeps the API helper for both, also a single principal. Blocker 2 -- no regression test. Adds test-issue-close-fail-closed.sh on the existing mocked-tea/sandboxed-git harness pattern. Asserts: a failed comment does not close the issue and exits non-zero; a successful comment does close it; the subcommand is top-level `tea comment`, never `tea issue comment`; and the comment and close carry the same --login. GREEN on this branch, RED on main. Severity correction. The original report said the issue closes anyway and the audit trail is silently lost. It does not: set -e at line 5 aborts the script when the comment fails, so the close is never reached. The real defect is that issue-close.sh -c cannot succeed at all where a tea login resolves -- loud, not silent. The explicit || guard is retained deliberately: a fail-closed property that depends on set -e disappears the moment anyone adds `|| true` or wraps the call in a conditional. Posted as a comment on #1081 and #1085. Refs #1081 Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Amf1Neca162odgcbCWMk1y
128 lines
4.2 KiB
Bash
Executable File
128 lines
4.2 KiB
Bash
Executable File
#!/bin/bash
|
|
# issue-close.sh - Close an issue on GitHub or Gitea
|
|
# Usage: issue-close.sh -i <issue_number> [-c <comment>]
|
|
|
|
set -e
|
|
|
|
# Source platform detection
|
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
source "$SCRIPT_DIR/detect-platform.sh"
|
|
|
|
# Parse arguments
|
|
ISSUE_NUMBER=""
|
|
COMMENT=""
|
|
|
|
while [[ $# -gt 0 ]]; do
|
|
case $1 in
|
|
-i|--issue)
|
|
ISSUE_NUMBER="$2"
|
|
shift 2
|
|
;;
|
|
-c|--comment)
|
|
COMMENT="$2"
|
|
shift 2
|
|
;;
|
|
-h|--help)
|
|
echo "Usage: issue-close.sh -i <issue_number> [-c <comment>]"
|
|
echo ""
|
|
echo "Options:"
|
|
echo " -i, --issue Issue number (required)"
|
|
echo " -c, --comment Comment to add before closing (optional)"
|
|
echo " -h, --help Show this help"
|
|
exit 0
|
|
;;
|
|
*)
|
|
echo "Unknown option: $1"
|
|
exit 1
|
|
;;
|
|
esac
|
|
done
|
|
|
|
if [[ -z "$ISSUE_NUMBER" ]]; then
|
|
echo "Error: Issue number is required (-i)"
|
|
exit 1
|
|
fi
|
|
|
|
# Detect platform and close issue
|
|
detect_platform >/dev/null
|
|
OWNER=$(get_repo_owner)
|
|
REPO=$(get_repo_name)
|
|
|
|
gitea_issue_comment_api() {
|
|
local host token url payload
|
|
host=$(get_remote_host) || return 1
|
|
token=$(get_gitea_token "$host") || return 1
|
|
url="https://${host}/api/v1/repos/${OWNER}/${REPO}/issues/${ISSUE_NUMBER}/comments"
|
|
payload=$(COMMENT="$COMMENT" python3 - <<'PY'
|
|
import json
|
|
import os
|
|
|
|
print(json.dumps({"body": os.environ["COMMENT"]}))
|
|
PY
|
|
)
|
|
curl -fsS -X POST \
|
|
-H "User-Agent: curl/8" \
|
|
-H "Authorization: token ${token}" \
|
|
-H "Content-Type: application/json" \
|
|
-d "$payload" \
|
|
"$url" >/dev/null
|
|
}
|
|
|
|
gitea_issue_close_api() {
|
|
local host token url
|
|
host=$(get_remote_host) || return 1
|
|
token=$(get_gitea_token "$host") || return 1
|
|
url="https://${host}/api/v1/repos/${OWNER}/${REPO}/issues/${ISSUE_NUMBER}"
|
|
curl -fsS -X PATCH \
|
|
-H "User-Agent: curl/8" \
|
|
-H "Authorization: token ${token}" \
|
|
-H "Content-Type: application/json" \
|
|
-d '{"state":"closed"}' \
|
|
"$url" >/dev/null
|
|
}
|
|
|
|
if [[ "$PLATFORM" == "github" ]]; then
|
|
if [[ -n "$COMMENT" ]]; then
|
|
gh issue comment "$ISSUE_NUMBER" --body "$COMMENT"
|
|
fi
|
|
gh issue close "$ISSUE_NUMBER"
|
|
echo "Closed GitHub issue #$ISSUE_NUMBER"
|
|
elif [[ "$PLATFORM" == "gitea" ]]; then
|
|
GITEA_LOGIN_NAME=$(get_gitea_login || true)
|
|
if [[ -n "$GITEA_LOGIN_NAME" ]]; then
|
|
if [[ -n "$COMMENT" ]]; then
|
|
# `tea issue comment` is NOT a subcommand -- tea 0.11.x lists only
|
|
# list/create/edit/reopen/close under `tea issue`. Comments are the
|
|
# TOP-LEVEL `tea comment`, which takes the same --repo/--login flags.
|
|
# The old call therefore always failed, was unchecked, and the script
|
|
# closed the issue anyway, losing the record of WHY.
|
|
#
|
|
# Use `tea comment` rather than the API helper so the comment and the
|
|
# close are made by the SAME principal ($GITEA_LOGIN_NAME). Routing the
|
|
# comment through the token-authenticated helper here would attribute the
|
|
# comment to the token holder and the close to the tea login -- two
|
|
# principals for one operation.
|
|
tea comment "$ISSUE_NUMBER" "$COMMENT" --repo "$OWNER/$REPO" --login "$GITEA_LOGIN_NAME" || {
|
|
echo "Error: failed to post comment on #$ISSUE_NUMBER -- NOT closing (fail closed)." >&2
|
|
exit 1
|
|
}
|
|
fi
|
|
tea issue close "$ISSUE_NUMBER" --repo "$OWNER/$REPO" --login "$GITEA_LOGIN_NAME"
|
|
else
|
|
echo "No tea login configured for $(get_remote_host); using authenticated Gitea API fallback." >&2
|
|
if [[ -n "$COMMENT" ]]; then
|
|
# Fail closed here too: an unchecked comment lets the issue close without its
|
|
# audit trail, which is the same defect as the tea path above.
|
|
gitea_issue_comment_api || {
|
|
echo "Error: failed to post comment on #$ISSUE_NUMBER -- NOT closing (fail closed)." >&2
|
|
exit 1
|
|
}
|
|
fi
|
|
gitea_issue_close_api
|
|
fi
|
|
echo "Closed Gitea issue #$ISSUE_NUMBER"
|
|
else
|
|
echo "Error: Unknown platform"
|
|
exit 1
|
|
fi
|