From 42f2fba31e51d08ca540c0d00e6e3da5cb1c7f57 Mon Sep 17 00:00:00 2001 From: Svilen Stefanov Date: Wed, 7 Oct 2026 00:34:42 +0200 Subject: [PATCH 1/2] feat: decide the credential from the inputs that are set, and let hosting choose its models Two rules from the licensing spec that need nothing from the backend. `llm` becomes optional (spec D-16). Without it, the inputs that are set decide: none means CodeBoarding hosting, one provider's inputs mean that provider, and inputs for several providers are refused as `several_provider_keys`, naming them. A workflow that names a provider is unchanged: it runs on that provider or fails, so the protected no-fallback test still holds. The webview's setup dialog is meant to write either no `with:` block or the one chosen provider's key. GitHub reads a missing secret as empty, so an unnamed workflow whose only key is missing runs on hosting. The log's first line and a new "Chosen" summary row say which source the run got and why, and a hosting run with no OIDC permission tells the reader to check that their secret exists. Hosting ignores the model inputs (spec D-13). On CodeBoarding's account the models are CodeBoarding's choice: `model`, `agent_model`, `parsing_model` and an inherited AGENT_MODEL or PARSING_MODEL never reach the engine there, a notice and a "Models" summary row name what was ignored, and the stored-analysis name leaves them out so it names the models that actually ran. Own-key runs keep their model inputs. Co-Authored-By: Claude Opus 5.5 --- AGENTS.md | 5 ++ README.md | 50 ++++++++------- action.yml | 19 +++--- scripts/action/credential_check.py | 96 ++++++++++++++++++++++------ scripts/action/verify-credentials.sh | 3 + scripts/action/with-auth.sh | 5 ++ tests/test_action_auth.py | 66 +++++++++++++++++++ tests/test_action_inputs.py | 22 ++++++- tests/test_llm_contract.py | 55 ++++++++++++++-- 9 files changed, 264 insertions(+), 57 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index fd9fbbd..3fe11d7 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -54,6 +54,11 @@ Protected tests: hosted tier, so a repository that had not added its secret yet went green while running on another vendor's model and CodeBoarding's money, silently. Any change that reintroduces a credential fallback breaks this test. + Since 7 October 2026 (licensing spec D-16, Svilen's call), a workflow that + names no `llm` is resolved from the provider inputs that are set, and runs on + hosting when none is. That covers only workflows that named nothing; a named + provider still runs on that provider or fails, and the job summary says which + source an unnamed workflow got and why. ## Releases diff --git a/README.md b/README.md index 838c669..6df8a57 100644 --- a/README.md +++ b/README.md @@ -50,9 +50,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 60 steps: - - uses: CodeBoarding/CodeBoarding-action@v1 - with: - llm: hosted # or a provider name -- see Authentication + - uses: CodeBoarding/CodeBoarding-action@v1 # CodeBoarding hosting; to use your own key, see Authentication ``` Automatic runs review both draft and non-draft pull requests and update one sticky **CodeBoarding review** comment. Opening, reopening, or pushing a commit runs analysis; changing only the draft state does not. A trusted repository owner, member, or collaborator can comment `/codeboarding` to analyze the current PR head again, including on fork PRs; every command creates a new result comment. @@ -106,35 +104,39 @@ Every review comment ends with a machine-readable HTML comment, `