目的 (Why)
Raised by the Opus seat in the review of #85 (PR #86), as a forward hazard, not a defect of that PR.
The act preflight's probe 2 — GET /repos/{reward_repo}/contents/ledger with SUPPORTER_LOOP_TOKEN MUST be 403/404 — is the push-impossibility proof (contract §8.4 v1.10). Fine-grained PATs get implicit read access to public repositories. If the reward repo (caty-ai/ask-ai-widget) is ever made public (contemplated in the contract's future-work notes), probe 2 returns 200 for a correctly scoped token and the preflight fails closed permanently — the same shape as #85, now on the only probe that proves the token cannot push. §8.4 already states "Implicit read access to public repos is a platform property of fine-grained PATs and is out of scope for the probe", but the code does not implement that exemption.
完了条件 (Done when)
触るファイル / モジュール予測
- .github/workflows/supporter-loop-reusable.yml
- supporter-loop/fixtures/workflow/test-interface.py
- (sister) caty-ai/x-collector docs/supporter-loop/CONTRACT.md
想定スコープ
Not urgent: the reward repo is private today and there is no plan to change that before the loop stabilises. Do not bundle into #85.
前提条件 (Blocked by)
#85 merged (so the base preflight is the v1.10 one).
目的 (Why)
Raised by the Opus seat in the review of #85 (PR #86), as a forward hazard, not a defect of that PR.
The
actpreflight's probe 2 —GET /repos/{reward_repo}/contents/ledgerwithSUPPORTER_LOOP_TOKENMUST be 403/404 — is the push-impossibility proof (contract §8.4 v1.10). Fine-grained PATs get implicit read access to public repositories. If the reward repo (caty-ai/ask-ai-widget) is ever made public (contemplated in the contract's future-work notes), probe 2 returns 200 for a correctly scoped token and the preflight fails closed permanently — the same shape as #85, now on the only probe that proves the token cannot push. §8.4 already states "Implicit read access to public repos is a platform property of fine-grained PATs and is out of scope for the probe", but the code does not implement that exemption.完了条件 (Done when)
GET /repos/{reward_repo}body.private == true, already fetched by probe 4 and currently discarded), or (b) keep the reward repo private as a hard precondition and add a preflight check that fails loud with an actionable message if.private != true.触るファイル / モジュール予測
想定スコープ
Not urgent: the reward repo is private today and there is no plan to change that before the loop stabilises. Do not bundle into #85.
前提条件 (Blocked by)
#85 merged (so the base preflight is the v1.10 one).