Repository navigation
feat: decide the credential from the inputs that are set, and refuse a model on hosting - #138
Draft
Svilen-Stefanov wants to merge 2 commits into
Draft
Svilen-Stefanov wants to merge 2 commits into
Svilen-Stefanov wants to merge 2 commits into
Conversation
…ting choose its models Two rules from the licensing spec that need nothing from the backend. `llm` becomes optional (spec D-16). Without it, the inputs that are set decide: none means CodeBoarding hosting, one provider's inputs mean that provider, and inputs for several providers are refused as `several_provider_keys`, naming them. A workflow that names a provider is unchanged: it runs on that provider or fails, so the protected no-fallback test still holds. The webview's setup dialog is meant to write either no `with:` block or the one chosen provider's key. GitHub reads a missing secret as empty, so an unnamed workflow whose only key is missing runs on hosting. The log's first line and a new "Chosen" summary row say which source the run got and why, and a hosting run with no OIDC permission tells the reader to check that their secret exists. Hosting ignores the model inputs (spec D-13). On CodeBoarding's account the models are CodeBoarding's choice: `model`, `agent_model`, `parsing_model` and an inherited AGENT_MODEL or PARSING_MODEL never reach the engine there, a notice and a "Models" summary row name what was ignored, and the stored-analysis name leaves them out so it names the models that actually ran. Own-key runs keep their model inputs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
CodeBoarding reviewStatus: 1 changed component See the full change in CodeBoarding. graph LR
n_action_scripts["action_scripts"]
classDef added fill:#1f883d,stroke:#0b5d23,color:#ffffff;
classDef modified fill:#bf8700,stroke:#7d4e00,color:#ffffff;
classDef deleted fill:#cf222e,stroke:#82071e,color:#ffffff,stroke-dasharray:5 3;
class n_action_scripts modified;
|
Hosting runs on CodeBoarding's account, so CodeBoarding chooses the models (spec D-13). The previous commit ignored a named model with a notice; this refuses the run instead, as `hosted_with_model`, before the checkout. A model named on a hosting run usually means the workflow meant to use its own key and the secret is missing, so when no `llm` is set the refusal says to check the secret. An AGENT_MODEL or PARSING_MODEL in the job's environment counts too, since the engine reads them. It also fixes the previous commit's wiring: the credential check never received the model inputs, so nothing could see them. With the refusal in place there is nothing to ignore, so the model-inputs output, the notice, the summary row and the gated analysis name are gone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #134. Two rules from the licensing spec (PR #39) that the Action can apply without anything from licensing-aws.
llmis optional (spec D-16)Without
llm, the inputs that are set decide:with:blockanthropic_api_keyonlyaws_bedrock_api_key+aws_bedrock_regionaws_bedrock_regiononlymissing_provider_key(it names Bedrock but configures nothing)anthropic_api_key+openai_api_keyseveral_provider_keys, naming both inputsllm: <provider>The webview's setup dialog should write one of two shapes, never every provider's key:
The trade-off. GitHub reads a secret that does not exist as an empty string, so an unnamed workflow whose only key is missing runs on hosting. What reports it:
id-token: write, which is refused with "If you meant to use your own provider key, check that its secret exists."A named provider still never falls back, so the protected test
test_a_named_provider_never_falls_back_to_codeboarding_credentialsis untouched and passes.AGENTS.mdrecords the decision next to it.Hosting refuses a named model (spec D-13)
A hosting run that sets
model,agent_modelorparsing_modelis refused before the checkout, with a new code,hosted_with_model. So is one with anAGENT_MODELorPARSING_MODELin the job's environment, because the engine reads those.llmset: the refusal says to check the key's secret. A model on a hosting run usually means the workflow meant to use its own key and the secret is missing.llm: hosted: the refusal says to remove the line, or to name the provider.The proxy-side model allowlist is still needed (review finding B2). This is only the Action's half.
Not in this PR (needs licensing-aws or the release)
/run/startand/run/finishin v2 form (fail loud, outcome names, run id in the relay)id-token: writefor own-key runsProposal: Action v2 Changes.
Testing
python -m unittest discover -s tests: everything passes excepttest_action_state…test_sync_without_baseline_uses_configured_depth_directly. That test fails identically on #134, because macOS bash 3.2 cannot run${FORCE_FULL,,}; CI runs bash 5.black==25.9.0andshellcheckare clean.🤖 Generated with Claude Code