Skip to content

feat: decide the credential from the inputs that are set, and refuse a model on hosting - #138

Draft
Svilen-Stefanov wants to merge 2 commits into
paywall/3-remove-licensefrom
paywall/3-credentials-and-models
Draft

Svilen-Stefanov wants to merge 2 commits into
paywall/3-remove-licensefrom
paywall/3-credentials-and-models

Conversation

@Svilen-Stefanov

@Svilen-Stefanov Svilen-Stefanov commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Stacked on #134. Two rules from the licensing spec (PR #39) that the Action can apply without anything from licensing-aws.

llm is optional (spec D-16)

Without llm, the inputs that are set decide:

Workflow Result
no with: block CodeBoarding hosting
anthropic_api_key only Anthropic, directly
aws_bedrock_api_key + aws_bedrock_region Bedrock (one provider, several inputs)
aws_bedrock_region only refused: missing_provider_key (it names Bedrock but configures nothing)
anthropic_api_key + openai_api_key refused: new code several_provider_keys, naming both inputs
llm: <provider> unchanged: that provider or a refusal

The webview's setup dialog should write one of two shapes, never every provider's key:

- uses: CodeBoarding/CodeBoarding-action@v1          # hosting
- uses: CodeBoarding/CodeBoarding-action@v1          # own key
  with:
    anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}

The trade-off. GitHub reads a secret that does not exist as an empty string, so an unnamed workflow whose only key is missing runs on hosting. What reports it:

  • the log's first line, for example "CodeBoarding is running on …, because no provider key is set";
  • a new "Chosen" row in the job summary;
  • a hosting run without id-token: write, which is refused with "If you meant to use your own provider key, check that its secret exists."

A named provider still never falls back, so the protected test test_a_named_provider_never_falls_back_to_codeboarding_credentials is untouched and passes. AGENTS.md records the decision next to it.

Hosting refuses a named model (spec D-13)

A hosting run that sets model, agent_model or parsing_model is refused before the checkout, with a new code, hosted_with_model. So is one with an AGENT_MODEL or PARSING_MODEL in the job's environment, because the engine reads those.

  • No llm set: the refusal says to check the key's secret. A model on a hosting run usually means the workflow meant to use its own key and the secret is missing.
  • llm: hosted: the refusal says to remove the line, or to name the provider.
  • Own-key runs keep their model inputs.

The proxy-side model allowlist is still needed (review finding B2). This is only the Action's half.

Not in this PR (needs licensing-aws or the release)

  • /run/start and /run/finish in v2 form (fail loud, outcome names, run id in the relay)
  • id-token: write for own-key runs
  • the refusal and unavailable comments
  • GitHub Enterprise Server

Proposal: Action v2 Changes.

Testing

python -m unittest discover -s tests: everything passes except test_action_state…test_sync_without_baseline_uses_configured_depth_directly. That test fails identically on #134, because macOS bash 3.2 cannot run ${FORCE_FULL,,}; CI runs bash 5.

  • New tests cover every deduction row above, the "Chosen" row, the id-token hint, and the model refusal (inputs, inherited variables, both messages, and the inputs reaching the check).
  • black==25.9.0 and shellcheck are clean.

🤖 Generated with Claude Code

…ting choose its models

Two rules from the licensing spec that need nothing from the backend.

`llm` becomes optional (spec D-16). Without it, the inputs that are set
decide: none means CodeBoarding hosting, one provider's inputs mean that
provider, and inputs for several providers are refused as
`several_provider_keys`, naming them. A workflow that names a provider is
unchanged: it runs on that provider or fails, so the protected
no-fallback test still holds. The webview's setup dialog is meant to write
either no `with:` block or the one chosen provider's key.

GitHub reads a missing secret as empty, so an unnamed workflow whose only
key is missing runs on hosting. The log's first line and a new "Chosen"
summary row say which source the run got and why, and a hosting run with
no OIDC permission tells the reader to check that their secret exists.

Hosting ignores the model inputs (spec D-13). On CodeBoarding's account
the models are CodeBoarding's choice: `model`, `agent_model`,
`parsing_model` and an inherited AGENT_MODEL or PARSING_MODEL never reach
the engine there, a notice and a "Models" summary row name what was
ignored, and the stored-analysis name leaves them out so it names the
models that actually ran. Own-key runs keep their model inputs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@codeboarding-review

codeboarding-review Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

CodeBoarding review

Status: 1 changed component

See the full change in CodeBoarding.

graph LR
    n_action_scripts["action_scripts"]
    classDef added fill:#1f883d,stroke:#0b5d23,color:#ffffff;
    classDef modified fill:#bf8700,stroke:#7d4e00,color:#ffffff;
    classDef deleted fill:#cf222e,stroke:#82071e,color:#ffffff,stroke-dasharray:5 3;
    class n_action_scripts modified;
Loading

download artifacts · run 37545861964

Hosting runs on CodeBoarding's account, so CodeBoarding chooses the models
(spec D-13). The previous commit ignored a named model with a notice; this
refuses the run instead, as `hosted_with_model`, before the checkout.

A model named on a hosting run usually means the workflow meant to use its
own key and the secret is missing, so when no `llm` is set the refusal says
to check the secret. An AGENT_MODEL or PARSING_MODEL in the job's
environment counts too, since the engine reads them.

It also fixes the previous commit's wiring: the credential check never
received the model inputs, so nothing could see them. With the refusal in
place there is nothing to ignore, so the model-inputs output, the notice,
the summary row and the gated analysis name are gone.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Svilen-Stefanov Svilen-Stefanov changed the title feat: decide the credential from the inputs that are set, and let hosting choose its models feat: decide the credential from the inputs that are set, and refuse a model on hosting Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant