Skip to content

chore: approve with the machine-user PAT when it exists - #13

Merged
wezell merged 1 commit into
mainfrom
chore/use-machine-user-approval-token
Sep 29, 2026
Merged

wezell merged 1 commit into
mainfrom
chore/use-machine-user-approval-token

Conversation

@wezell

@wezell wezell commented Sep 29, 2026

Copy link
Copy Markdown
Member

What

DOTBOT_GITHUB_USER_PAT now exists in this repo, so the review workflow can approve as the machine user instead of as github-actions[bot]:

          github_approval_token: ${{ secrets.DOTBOT_GITHUB_USER_PAT || github.token }}

Why prefer the PAT:

  • The approval is attributed to a real user (dotCMS-Machine-User) rather than a bot identity.
  • It is independent of the repo-level "Allow GitHub Actions to create and approve pull requests" setting.
  • The workflow token stays as the fallback, so consumer repos without the secret still approve (github-actions[bot]) — that path is what feat: DOTBOT_ACT_MODEL for the act model, plus the fixes that unblock dotbot approval #7 wired and what has been approving here since.

Caveat carried into the comment and README: GitHub rejects an approval from the PR author, so the PAT's user must differ from whoever opened the PR (a warning, never a failed run, if it is misconfigured).

Commit statuses stay on github.token so they don't depend on the PAT.

Verification

  • uv run pytest -q → 808 passed; pre-commit run --all-files → Passed; actionlint → clean
  • The PR's own review run is the test: the approval should now appear as dotCMS-Machine-User instead of github-actions[bot]

DOTBOT_GITHUB_USER_PAT now exists in this repo, so the review workflow should use
it rather than settling for a bot-identity approval:

  github_approval_token: ${{ secrets.DOTBOT_GITHUB_USER_PAT || github.token }}

The machine-user PAT is preferred — the approval is attributed to a real user
(the token's user must not be the PR author, or GitHub rejects it), and
`github.token` remains the fallback so consumer repos without the secret still
get approvals (as github-actions[bot]).

Docs and the workflow assertion move to the combined expression; the commit
statuses stay on the workflow token so they do not depend on the PAT.
@github-actions

Copy link
Copy Markdown

dotbot code review:

  • Reviewer: meta/muse-spark-1.3 (medium)
  • Overall: patch is correct
  • New findings this run: 0
  • Prior unresolved dotbot findings still relevant: 0
  • Active findings total: 0

Prefers machine-user PAT with workflow-token fallback for approval, keeps statuses on github.token, with matching README and test updates. No correctness, security, or atomicity defect introduced.

Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads.

reviewed by dotbot · meta/muse-spark-1.3 · medium

@github-actions

Copy link
Copy Markdown

dotbot code review:

  • Reviewer: ~z-ai/glm-latest (medium)
  • Overall: patch is correct
  • New findings this run: 0
  • Prior unresolved dotbot findings still relevant: 0
  • Active findings total: 0

The change consistently switches the approval token to prefer secrets.DOTBOT_GITHUB_USER_PAT with a github.token fallback across the workflow, README, and the test that pins the workflow content. The fallback expression is valid GitHub Actions syntax (missing secrets evaluate falsy), and the author-mismatch requirement is documented in the comments.

Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads.

reviewed by dotbot · ~z-ai/glm-latest · medium

@dotCMS-Machine-User dotCMS-Machine-User left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ dotbot review: all reviewer models (meta/muse-spark-1.3, ~z-ai/glm-latest) agree — patch is correct.

approved automatically by dotbot

@wezell
wezell merged commit de93a1b into main Sep 29, 2026
4 checks passed
@wezell
wezell deleted the chore/use-machine-user-approval-token branch September 29, 2026 16:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants