A deploy key cannot close its own repository's issue by full path #213

closed cmc opened this on 2026-09-11 18:42 UTC

Discussion

cmc 2026-09-11 18:42 UTC

Since #203 a cross-repository close requires policy.ScopeAllowsGit(scope, target, write) in addition to write on the target, and ScopeAllowsGit rejects every deploy: scope. So a deploy-key push whose message says Closes owner/self#N, naming the repository it is bound to by full path, closes nothing, while a bare Closes #N in the same commit closes as before.

This is the security rule working as intended (a deploy key never acts outside its binding), but it will read as a bug to someone who writes full paths habitually. Either allow the self-path case when the target is the bound repository, or document it on the Users page. Decide and record.

Found during the #203 review.

closed by commit ec8b566b11 by cmc: control, e2e, wiki: a deploy key closes its own repository's issue by full path

2026-09-11 23:42 UTC