diff --git a/.claude/hooks/.diagnostics_state.json b/.claude/hooks/.diagnostics_state.json index e8c560b2..3b4e22f2 100644 --- a/.claude/hooks/.diagnostics_state.json +++ b/.claude/hooks/.diagnostics_state.json @@ -1 +1 @@ -{"file": "/home/patrick/Projects/AIPass/src/aipass/flow/apps/modules/registry_monitor.py", "errors": [{"line": 39, "message": "E402: Module level import not at top of file"}, {"line": 42, "message": "E402: Module level import not at top of file"}, {"line": 45, "message": "E402: Module level import not at top of file"}, {"line": 48, "message": "E402: Module level import not at top of file"}, {"line": 51, "message": "E402: Module level import not at top of file"}, {"line": 102, "message": "F821: Undefined name `start_monitoring_impl`"}, {"line": 120, "message": "F821: Undefined name `stop_monitoring_impl`"}, {"line": 195, "message": "E501: Line too long (121 > 120)"}, {"line": 222, "message": "F821: Undefined name `time`"}, {"line": 101, "message": "\"start_monitoring_impl\" is not defined"}, {"line": 119, "message": "\"stop_monitoring_impl\" is not defined"}, {"line": 221, "message": "\"time\" is not defined"}]} \ No newline at end of file +{"file": "/home/patrick/Projects/AIPass/src/aipass/flow/apps/modules/post_close_runner.py", "errors": [{"line": 30, "message": "E402: Module level import not at top of file"}, {"line": 31, "message": "E402: Module level import not at top of file"}, {"line": 34, "message": "E402: Module level import not at top of file"}, {"line": 42, "message": "E402: Module level import not at top of file"}, {"line": 43, "message": "E402: Module level import not at top of file"}]} \ No newline at end of file diff --git a/src/aipass/drone/apps/plugins/devpulse_ops/__pycache__/auth.cpython-312.pyc b/src/aipass/drone/apps/plugins/devpulse_ops/__pycache__/auth.cpython-312.pyc index 7b7741bd..e6deca64 100644 Binary files a/src/aipass/drone/apps/plugins/devpulse_ops/__pycache__/auth.cpython-312.pyc and b/src/aipass/drone/apps/plugins/devpulse_ops/__pycache__/auth.cpython-312.pyc differ diff --git a/src/aipass/drone/apps/plugins/devpulse_ops/auth.py b/src/aipass/drone/apps/plugins/devpulse_ops/auth.py index f8a0fb1d..8e0d9049 100644 --- a/src/aipass/drone/apps/plugins/devpulse_ops/auth.py +++ b/src/aipass/drone/apps/plugins/devpulse_ops/auth.py @@ -25,18 +25,10 @@ from aipass.seedgo.apps.modules.permissions import TRUSTED_CROSS_WRITERS ALLOWED_CALLERS: list[str] = list(TRUSTED_CROSS_WRITERS) -def verify_caller() -> str: - """Verify the calling branch is authorized for devpulse operations. +def _find_caller() -> str: + """Walk up from CWD to find passport.json and return branch name. - Walks up from CWD looking for ``.trinity/passport.json``, reads the - branch name, and checks it against :data:`ALLOWED_CALLERS`. - - Returns: - The caller's branch name if authorized. - - Raises: - PermissionError: If the caller is not in the allowed list or no - passport can be found. + Returns the branch name, or raises PermissionError if no passport found. """ current = Path.cwd().resolve() for _ in range(10): @@ -52,15 +44,6 @@ def verify_caller() -> str: msg = f"Passport at {passport_path} has no branch_name" logger.error(msg) raise PermissionError(msg) - if name not in ALLOWED_CALLERS: - msg = f"Branch '{name}' is not authorized for system-pr. Trusted cross-writers: {ALLOWED_CALLERS}" - logger.error(msg) - raise PermissionError(msg) - json_handler.log_operation( - "devpulse_auth_verify", - {"caller": name, "passport": str(passport_path)}, - ) - logger.info("Caller '%s' authorized for devpulse operations", name) return name except PermissionError: raise @@ -75,3 +58,28 @@ def verify_caller() -> str: msg = "No .trinity/passport.json found in directory hierarchy — cannot verify caller" logger.error(msg) raise PermissionError(msg) + + +def verify_caller() -> str: + """Verify the calling branch is authorized for devpulse operations. + + system-pr, merge, smart-sync, fix are restricted to ALLOWED_CALLERS. + Other branches use drone @git pr for their own branch-scoped PRs. + + Returns: + The caller's branch name if authorized. + + Raises: + PermissionError: If the caller is not in ALLOWED_CALLERS. + """ + name = _find_caller() + if name not in ALLOWED_CALLERS: + msg = f"Branch '{name}' is not authorized for this operation. Use 'drone @git pr' for branch-scoped PRs." + logger.error(msg) + raise PermissionError(msg) + json_handler.log_operation( + "devpulse_auth_verify", + {"caller": name, "passport": "verified"}, + ) + logger.info("Caller '%s' authorized for devpulse operations", name) + return name