Skip to content

Add per-command org-member permissions - #542

Draft
timja with Copilot wants to merge 2 commits into
mainfrom
copilot/allow-restricting-to-org-members
Draft

timja with Copilot wants to merge 2 commits into
mainfrom
copilot/allow-restricting-to-org-members

Conversation

Copilot AI commented Jul 25, 2026 •

Copy link
Copy Markdown
Contributor

This adds optional command-level permission controls so repositories can restrict specific comment-ops commands to organization members. By default, commands remain open to all commenters, preserving current behavior.

  • Per-command permission model

    • Add permission to each command config
    • Support:
      • all (default): any commenter may invoke the command
      • member: only org MEMBER and OWNER authors may invoke the command
  • Authorization enforcement

    • Extend command enablement checks to evaluate the comment/review author's GitHub author_association
    • Apply permission checks consistently across all supported commands:
      • close
      • reopen
      • label
      • remove-label
      • reviewer
      • transfer
  • Config and docs

    • Update default config to include permission: all
    • Document the new option in the README with supported values and behavior
  • Test coverage

    • Add focused tests for:
      • default behavior when permission is unset
      • member access for org members/owners
      • denial for non-members
      • extraction of author association from webhook payloads

Example configuration:

commands:
  label:
    enabled: true
    permission: member
    allowedLabels: [bug, chore, enhancement]

  close:
    enabled: true
    permission: all

Copilot AI linked an issue Jul 25, 2026 that may be closed by this pull request
Copilot AI changed the title [WIP] Add option to restrict commands to org members Add per-command org-member permissions Jul 25, 2026
Copilot finished work on behalf of timja July 25, 2026 08:03
Copilot AI requested a review from timja July 25, 2026 08:03
@timja
timja requested a balanced review from Copilot October 7, 2026 20:56

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

Permission enforcement is consistently implemented, backward-compatible, documented, and adequately tested.

0 open findings

What changed in this PR

Adds optional per-command organization-member authorization while preserving open access by default.

Changes:

  • Adds all and member permission levels.
  • Extracts webhook author associations and enforces permissions across all commands.
  • Updates defaults, documentation, and tests.
File Description
README.md Documents permission configuration.
app/​default-config.js Adds default all permissions.
app/​comment-extractor.js Extracts author associations.
app/​comment-extractor.test.js Tests payload extraction.
app/​command-enabled.js Implements permission enforcement.
app/​command-enabled.test.js Tests member and default access.
app/​commands/​close-command.js Passes author association.
app/​commands/​reopen-command.js Passes author association.
app/​commands/​label-command.js Passes author association.
app/​commands/​remove-label-command.js Passes author association.
app/​commands/​reviewer-command.js Passes author association.
app/​commands/​transfer-command.js Passes author association.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow restricting to org members

3 participants