Repository navigation
Conversation
potiuk
added this pull request to stack #1586
October 10, 2026 09:23
potiuk
force-pushed
the
perf/pr-mgmt-10-mention-allowlist
branch
2 times, most recently
from
October 10, 2026 10:18
dcd8d02 to
d9a6991
Compare
Every pr-management renderer keeps only the PR author's @-mention live
and backtick-quotes every other handle, and the agent-guard `mention`
guard refuses the rest. There was no way for a project to say "this
bot / this team may be mentioned" short of a per-command override.
A new `mention_allowlist` key in `pr-management-config.md` names the
handles and teams that stay live, honoured by one shared helper in
every renderer — triage notes, stale-sweep comments, mentor comments
and code-review bodies — and by the guard on every surface it checks
(comments, folded notes, reviews, `gh api` writes). One call can add a
handle with `--allow-mention <login>`, paired with
`MAGPIE_ALLOW_MENTIONS=1` on the posting command so the exception is
explicit in both places.
The guard reads the allowlist, and the mentoring hand-off team, from
`.apache-magpie-overrides/` as GitHub serves it from the target
repository's default branch — not from the local checkout, which the
agent can edit, commit to, or swap for a scratch repository. Only a
reviewed, merged change can widen what may be mentioned. The target
must be explicit and unambiguous: `--repo` and/or a PR or issue URL as
the selector, all agreeing, or a plain `repos/OWNER/REPO/…` endpoint
for `gh api`; there is no fallback to the checkout's repository, a URL
in body text does not count, an endpoint with `.`/`..` segments,
percent-encoding or `{owner}` placeholders is refused, and GraphQL
writes get no allowlist. This replaces the local committed-file check
the hand-off exemption used.
Generated-by: Claude Opus 5
Claude-Session: https://claude.ai/code/session_01GTPsZ5aEE5bUVYqp47Dpvv
…n target gh accepts `-ROWNER/REPO` as well as `-R OWNER/REPO` and `--repo=`, and the last value wins. The mention guard read only the separated and `=` forms, so `gh pr comment 5 --repo acme/product -Rvictim/other` posted to victim/other while the guard applied acme/product's allowlist. Every spelling now counts, and two that disagree leave the target ambiguous, so no allowlist applies. Generated-by: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01GTPsZ5aEE5bUVYqp47Dpvv
…ntion target The mention guard found the target repository by scanning tokens, so a flag's value could pass for a repository: `gh pr comment 5 --body "-Racme/product @bob"` made the guard apply acme/product's allowlist while gh posted to the checkout's repository. The arguments are now read the way gh reads them, with each flag's arity for the comment, edit and review commands: a value is never taken for `--repo` or the selector. A line the guard cannot read for certain — an unknown flag, combined short flags, a second positional, or a second `gh api` endpoint — names no target, so no allowlist applies. Generated-by: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01GTPsZ5aEE5bUVYqp47Dpvv
potiuk
force-pushed
the
perf/pr-mgmt-10-mention-allowlist
branch
from
October 10, 2026 11:16
d9a6991 to
f3c0d0e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
pr-managementrenderer keeps only the PR author's @-mention live and backtick-quotes every other handle, and the agent-guardmentionguard refuses the rest. A project had no way to say "this bot / this team may be mentioned" short of a per-command override.mention_allowlistkey inpr-management-config.mdnames handles and teams that stay live. One shared helper honours it in every renderer (triage notes, stale-sweep comments, mentor comments, code-review bodies), and so does the guard on every surface it checks (comments, folded notes, reviews,gh apiwrites).--allow-mention <login>, paired withMAGPIE_ALLOW_MENTIONS=1on the posting command, so the exception is explicit in both places.Top of the stack.
Security notes
.apache-magpie-overrides/as GitHub serves it from the target repository's default branch, not from the local checkout, which the agent can edit, commit to, or swap for a scratch repository. Only a reviewed, merged change can widen what may be mentioned. This replaces the local committed-file check the hand-off exemption used in the bottom PR of the stack.--repoand/or a PR or issue URL as the selector, all agreeing, or a plainrepos/OWNER/REPO/…endpoint forgh api.cdorGH_REPOearlier on the line could redirect../..segments, percent-encoding or{owner}placeholders are refused.gh's arguments the wayghdoes, with each flag's arity for the comment, edit and review commands, so a flag's value (--body "-Racme/x @bob") is never taken for--repoor the selector; the attached-ROWNER/REPOform counts, and an unknown flag, combined short flags or an extra positional leave the target ambiguous.Type of change
Test plan
prek run --all-filespassestools/pr-managementpytest (tests/test_mentions.py)Was generative AI tooling used to co-author this PR?
Generated-by:.🤖 Generated with Claude Code
https://claude.ai/code/session_01GTPsZ5aEE5bUVYqp47Dpvv