mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-03 17:17:36 +02:00
fix(actions): harden fork pull request run approval (#39399)
Fixes several gaps in the approval of fork pull request runs: 1. Approving a run that was cancelled while awaiting approval revived its cancelled jobs. Such a run is no longer treated as awaiting approval by the merge box, run page, approve actions and API, and rerunning it approves it. 2. Approval no longer revives jobs cancelled while the run was pending, no longer lets two jobs sharing a concurrency group cancel each other, and re-emits the run so jobs needing a cancelled job get resolved. 3. An unapproved run applies its workflow-level concurrency only once approved. 4. For workflows from the pull request, both the event actor and the pull request author must be trusted to skip approval. Workflows from the default branch, like `issue_comment`, still only check the actor. --------- Co-authored-by: silverwind <me@silverwind.io>
This commit is contained in:
1 parent
031c5f1ba6
commit
f44e64be81
12 files changed
+214
-54
No files matched your search
@@ -196,11 +196,11 @@ func ApproveWorkflowRun(ctx *context.APIContext) {
|
||||
return
|
||||
}
|
||||
|
||||
if !run.NeedApproval {
|
||||
if !run.IsAwaitingApproval() {
|
||||
// Approving twice is idempotent, but a run that never awaited approval gets 409 rather
|
||||
// than GitHub's 403, which would be indistinguishable from a permission denial.
|
||||
if run.ApprovedBy == 0 {
|
||||
ctx.APIError(http.StatusConflict, "run does not require approval")
|
||||
ctx.APIError(http.StatusConflict, "run is not waiting for approval")
|
||||
return
|
||||
}
|
||||
respondRepoActionWorkflowRun(ctx, run)
|
||||
|
||||
Reference in new issue
Block a user