Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions guards/github-guard/rust-guard/src/labels/constants.rs
Original file line number Diff line number Diff line change
Expand Up @@ -143,6 +143,7 @@ pub mod field_names {
pub const AUTHOR_ASSOCIATION_CAMEL: &str = "authorAssociation";
pub const LOGIN: &str = "login";
pub const IS_ERROR: &str = "isError";
pub const COMMENT_NODE_ID: &str = "commentNodeID";
}

/// Canonical repo `visibility` field string values, used to avoid silent
Expand Down
39 changes: 17 additions & 22 deletions guards/github-guard/rust-guard/src/labels/tool_rules.rs
Original file line number Diff line number Diff line change
Expand Up @@ -862,7 +862,7 @@ pub fn apply_tool_labels(
baseline_scope = Cow::Owned(format!(
"node/{}",
tool_args
.get("commentNodeID")
.get(field_names::COMMENT_NODE_ID)
.and_then(|v| v.as_str())
.unwrap_or("")
));
Expand All @@ -872,7 +872,7 @@ pub fn apply_tool_labels(
&repo,
repo_id,
tool_args
.get("commentNodeID")
.get(field_names::COMMENT_NODE_ID)
.and_then(|v| v.as_str())
.unwrap_or(""),
&mut secrecy,
Expand All @@ -890,7 +890,7 @@ pub fn apply_tool_labels(
baseline_scope = Cow::Owned(format!(
"node/{}",
tool_args
.get("commentNodeID")
.get(field_names::COMMENT_NODE_ID)
.and_then(|v| v.as_str())
.unwrap_or("")
));
Expand All @@ -900,7 +900,7 @@ pub fn apply_tool_labels(
&repo,
repo_id,
tool_args
.get("commentNodeID")
.get(field_names::COMMENT_NODE_ID)
.and_then(|v| v.as_str())
.unwrap_or(""),
&mut secrecy,
Expand Down Expand Up @@ -1131,6 +1131,16 @@ mod tests {
PolicyContext::default()
}

/// Tools routed through `apply_governance_labels` (repo/org/enterprise-scoped
/// governance metadata reads and writes). Shared across the three governance
/// test functions below to avoid drift when a new governance tool is added.
const GOVERNANCE_TOOLS: [&str; 4] = [
"repository_ruleset_read",
"custom_properties_read",
"custom_properties_write",
"create_repository_ruleset",
];

fn private_label(owner: &str, repo: &str, repo_id: &str, ctx: &PolicyContext) -> Vec<String> {
super::policy_private_scope_label(owner, repo, repo_id, ctx)
}
Expand Down Expand Up @@ -1715,12 +1725,7 @@ mod tests {
);
assert_eq!(integrity, none_integrity(repo_id, &ctx));

let governance_tools = [
"repository_ruleset_read",
"custom_properties_read",
"custom_properties_write",
"create_repository_ruleset",
];
let governance_tools = GOVERNANCE_TOOLS;
for tool in governance_tools {
let (secrecy, integrity, _) = super::apply_tool_labels(
tool,
Expand Down Expand Up @@ -1947,12 +1952,7 @@ mod tests {
assert_eq!(secrecy, expected_secrecy);
assert_eq!(integrity, writer_integrity(repo_id, &ctx));

for tool in &[
"repository_ruleset_read",
"custom_properties_read",
"custom_properties_write",
"create_repository_ruleset",
] {
for tool in &GOVERNANCE_TOOLS {
let (secrecy, integrity, _) =
super::apply_tool_labels(tool, &args, repo_id, vec![], vec![], String::new(), &ctx);
assert_eq!(secrecy, expected_secrecy, "{tool} secrecy");
Expand All @@ -1973,12 +1973,7 @@ mod tests {
("enterprise", "enterprise", "github-enterprise"),
] {
let args = serde_json::json!({"level": level, field: scope});
for tool in &[
"repository_ruleset_read",
"custom_properties_read",
"custom_properties_write",
"create_repository_ruleset",
] {
for tool in &GOVERNANCE_TOOLS {
let (secrecy, integrity, _) =
super::apply_tool_labels(tool, &args, "", vec![], vec![], String::new(), &ctx);
assert_eq!(
Expand Down
Loading