Skip to content

ci(cla): auto-record portal signatures + label server-side - #3

Merged
ajianaz merged 2 commits into
mainfrom
ci/cla-sync-automation
Sep 10, 2026
Merged

ajianaz merged 2 commits into
mainfrom
ci/cla-sync-automation

Conversation

@ajianaz

@ajianaz ajianaz commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

What

  • New .github/workflows/cla-sync.yml: listens for [CLA] Signature issues from the signing portal (https://codecoradev.github.io/cla/), validates them (issue opener must equal the claimed GitHub user — matches the portal's OAuth auto-fill; CLA type must be individual/corporate), appends the entry to .cla/signatures.json (idempotent on re-sign), applies the cla-signature label server-side, opens an auto-generated PR for owner approval, comments on the issue, and closes it.
  • cla-check.yml: bot comment now instructs contributors to wait for the green submit confirmation before closing the tab.
  • Requires new secret OWNER_PAT (classic PAT, public_repo scope is sufficient for this public repo) — org default workflow permission is read, so ${{ secrets.GITHUB_TOKEN }} cannot push or apply labels.

Why

  • Portal submissions were broken end-to-end: (1) the portal's issue POST included a label the contributor token cannot create → 403 (see fix(cla): create signature issue without labels codecoradev.github.io#2); (2) even when an issue landed, signatures.json was only ever updated by manual owner commits. cla-sync closes both gaps so a contributor's only action is signing.

Testing

  • Validation logic reviewed against the exact issue body template the portal generates (field regexes match - **Name:** etc.)
  • Identity guard: issue opener != claimed user → rejected with explanation
  • Idempotency: re-signing replaces the existing entry for the same username
  • Label now pre-exists on this repo (created via API, green #0E8A16) and is re-applied server-side by cla-sync
  • End-to-end live test pending merge (fire a test issue after OWNER_PAT is set)

Portal signature issues could never be processed into
.cla/signatures.json without a manual owner commit. New cla-sync
workflow: on [CLA] Signature issue -> validate identity (issue opener
must equal claimed GitHub user, matching the portal's OAuth auto-fill)
-> append to signatures.json (idempotent re-sign) -> apply the
cla-signature label server-side (contributors cannot create labels)
-> open an auto-generated PR for owner approval -> comment + close.

cla-check bot comment now tells contributors to wait for the green
submit confirmation, so a silently failed submission is noticed
immediately.

Requires secret OWNER_PAT (contents:write on this repo) — org default
workflow token is read-only.
…ion)

Cora review flagged CRITICAL: attacker-controlled outputs (issue body)
interpolated via ${{ }} into github-script source. Read them through
process.env instead. Also: don't close the issue when the PR step
failed, so a failed submission stays open with the failure comment as
the audit trail.
@ajianaz
ajianaz merged commit d285f5c into main Sep 10, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant