Since #203 a cross-repository close requires policy.ScopeAllowsGit(scope, target, write) in addition to write on the target, and ScopeAllowsGit rejects every deploy: scope. So a deploy-key push whose message says Closes owner/self#N, naming the repository it is bound to by full path, closes nothing, while a bare Closes #N in the same commit closes as before.
This is the security rule working as intended (a deploy key never acts outside its binding), but it will read as a bug to someone who writes full paths habitually. Either allow the self-path case when the target is the bound repository, or document it on the Users page. Decide and record.
Found during the #203 review.
closed by commit ec8b566b11 by cmc: control, e2e, wiki: a deploy key closes its own repository's issue by full path
2026-09-11 23:42 UTC