Add fail-closed author allowlist gating job dispatch
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

Sessions run claude with --dangerously-skip-permissions and a prompt built
from issue/PR/comment text, so only trusted authors may supply that text.
teabot now dispatches a job only when the triggering event's author login is
on an allowlist; an empty allowlist dispatches nothing (fail-closed).

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
This commit is contained in:
2026-07-27 00:33:09 +10:00
parent 3be3f4cc46
commit 748048be50
14 changed files with 413 additions and 6 deletions
+17
View File
@@ -36,6 +36,23 @@ claude_config_dir: ~/.claude
# Optional: override the state directory (default ~/.local/state/teabot).
# state_dir: ~/.local/state/teabot
# SECURITY: author allowlist. Jobs run with --dangerously-skip-permissions in a
# container whose prompt is built from issue/PR/comment TEXT, so only trusted
# authors may supply that text. teabot dispatches a job only when the event's
# author login is listed here. Events from anyone else are recorded (so they do
# not re-trigger) and logged, but never spawn a container. This is fail-closed:
# an empty/absent list dispatches NOTHING.
allowed_authors:
- benvin
# Optional per-repo override. A present entry fully replaces allowed_authors for
# that repo (an empty list disables dispatch for it); absent falls back to the
# global list above.
# repo_allowed_authors:
# unkin/teabot:
# - benvin
# - trusted-colleague
# Bot personalities. Each is a distinct Gitea account backed by its own tea
# config file (create it with: tea logins add --name <bot> ...). teabot reads
# the token + username from that file and mounts it into the container so tea