Add fail-closed author allowlist gating job dispatch
Sessions run claude with --dangerously-skip-permissions and a prompt built from issue/PR/comment text, so only trusted authors may supply that text. teabot now dispatches a job only when the triggering event's author login is on an allowlist; an empty allowlist dispatches nothing (fail-closed). Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
This commit is contained in:
@@ -36,6 +36,23 @@ claude_config_dir: ~/.claude
|
||||
# Optional: override the state directory (default ~/.local/state/teabot).
|
||||
# state_dir: ~/.local/state/teabot
|
||||
|
||||
# SECURITY: author allowlist. Jobs run with --dangerously-skip-permissions in a
|
||||
# container whose prompt is built from issue/PR/comment TEXT, so only trusted
|
||||
# authors may supply that text. teabot dispatches a job only when the event's
|
||||
# author login is listed here. Events from anyone else are recorded (so they do
|
||||
# not re-trigger) and logged, but never spawn a container. This is fail-closed:
|
||||
# an empty/absent list dispatches NOTHING.
|
||||
allowed_authors:
|
||||
- benvin
|
||||
|
||||
# Optional per-repo override. A present entry fully replaces allowed_authors for
|
||||
# that repo (an empty list disables dispatch for it); absent falls back to the
|
||||
# global list above.
|
||||
# repo_allowed_authors:
|
||||
# unkin/teabot:
|
||||
# - benvin
|
||||
# - trusted-colleague
|
||||
|
||||
# Bot personalities. Each is a distinct Gitea account backed by its own tea
|
||||
# config file (create it with: tea logins add --name <bot> ...). teabot reads
|
||||
# the token + username from that file and mounts it into the container so tea
|
||||
|
||||
Reference in New Issue
Block a user