From c62ba0ca2568709eca9967cdec773ef9fef8947a Mon Sep 17 00:00:00 2001 From: Tudor Date: Fri, 3 Jul 2026 13:39:59 +0100 Subject: [PATCH] fix(ci): post AI review comments with the run-scoped Gitea token MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit REGISTRY_TOKEN lacks issue-write scope (403 on comment post). Gitea Actions auto-provides a repo-scoped per-run token as secrets.GITEA_TOKEN — no user-managed secret needed. Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_01PqGhF93UrpDNvXBLMjJENL --- .gitea/workflows/pr-checks.yml | 3 ++- docs/DEPLOY.md | 7 ++++--- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/.gitea/workflows/pr-checks.yml b/.gitea/workflows/pr-checks.yml index b0859a5..0a50c0a 100644 --- a/.gitea/workflows/pr-checks.yml +++ b/.gitea/workflows/pr-checks.yml @@ -178,7 +178,8 @@ jobs: - name: Review PR diff with Claude Code env: CLAUDE_CODE_OAUTH_TOKEN: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} - GITEA_TOKEN: ${{ secrets.REGISTRY_TOKEN }} + # Auto-provided per-run token from Gitea Actions (repo-scoped) + GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} GITEA_SERVER_URL: ${{ gitea.server_url }} GITEA_REPOSITORY: ${{ gitea.repository }} PR_NUMBER: ${{ gitea.event.pull_request.number }} diff --git a/docs/DEPLOY.md b/docs/DEPLOY.md index e7ca948..6080777 100644 --- a/docs/DEPLOY.md +++ b/docs/DEPLOY.md @@ -56,7 +56,7 @@ fail the E2E gate. That's the point: staging absorbs the risk. | Secret | Purpose | |---|---| -| `REGISTRY_TOKEN` | push images to the registry + post PR review comments (already set) | +| `REGISTRY_TOKEN` | push images to privaterepo.sitaru.org (already set) | | `CLAUDE_CODE_OAUTH_TOKEN` | Claude Code subscription auth for the PR review — generate with `claude setup-token` on your machine | | `PORTAINER_STAGING_WEBHOOK` | staging stack redeploy webhook URL | | `PORTAINER_PROD_WEBHOOK` | production stack redeploy webhook URL | @@ -125,7 +125,8 @@ numbers, so scheduled data refreshes don't break the gate. `scripts/ci/ai_review.py` pipes the PR diff through headless Claude Code (`claude -p`, authenticated with the subscription OAuth token — no API -billing), posts the structured findings as a PR comment via the Gitea API -(reusing `REGISTRY_TOKEN`), and fails the check only when a finding is rated +billing), posts the structured findings as a PR comment using the per-run +token Gitea Actions provides automatically (`secrets.GITEA_TOKEN` — no setup +needed), and fails the check only when a finding is rated **severe** (would break prod, leak data, or corrupt data). Minor findings are informational and never block a merge.