Skip to content

supporter-loop: act preflight probe 2 (Contents 403/404) fails closed permanently if the reward repo ever becomes public (Opus seat, #85 follow-up) #87

Description

@shojikumaru

目的 (Why)

Raised by the Opus seat in the review of #85 (PR #86), as a forward hazard, not a defect of that PR.

The act preflight's probe 2 — GET /repos/{reward_repo}/contents/ledger with SUPPORTER_LOOP_TOKEN MUST be 403/404 — is the push-impossibility proof (contract §8.4 v1.10). Fine-grained PATs get implicit read access to public repositories. If the reward repo (caty-ai/ask-ai-widget) is ever made public (contemplated in the contract's future-work notes), probe 2 returns 200 for a correctly scoped token and the preflight fails closed permanently — the same shape as #85, now on the only probe that proves the token cannot push. §8.4 already states "Implicit read access to public repos is a platform property of fine-grained PATs and is out of scope for the probe", but the code does not implement that exemption.

完了条件 (Done when)

  • Decide the shape: (a) gate probe 2 on the reward repo being private (GET /repos/{reward_repo} body .private == true, already fetched by probe 4 and currently discarded), or (b) keep the reward repo private as a hard precondition and add a preflight check that fails loud with an actionable message if .private != true.
  • Contract §8.4 amended accordingly (post-freeze, version bump).
  • Fixture/static assertion covering the chosen shape.

触るファイル / モジュール予測

  • .github/workflows/supporter-loop-reusable.yml
  • supporter-loop/fixtures/workflow/test-interface.py
  • (sister) caty-ai/x-collector docs/supporter-loop/CONTRACT.md

想定スコープ

Not urgent: the reward repo is private today and there is no plan to change that before the loop stabilises. Do not bundle into #85.

前提条件 (Blocked by)

#85 merged (so the base preflight is the v1.10 one).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions