fabro/lib/crates/fabro-cli/tests/it/cmd
fabro-sh-0530[bot] e40dc7d9ad
Move GitHub token permissions to [run.integrations.github.permissions] (#215)
## Summary

Token scopes describe what *a run* is authorized to do, not server
identity. Today they live under
`[server.integrations.github.permissions]`, which can't be overridden by
`workflow.toml` / `project.toml` (server keys are stripped from
per-workflow layers) — so projects and workflows can't tighten or relax
permissions despite the docs already advertising a per-run config. This
PR moves them under `[run.integrations.github.permissions]`, where the
standard layer-merge (workflow > project > user > defaults) Just Works.
Greenfield, no migration shim.

## What changed

- **New layer/resolved types** in `fabro-config` and `fabro-types`:
`RunIntegrationsLayer`, `RunIntegrationsGithubLayer`, and resolved
counterparts. `permissions` becomes a flat `HashMap<String,
InterpString>` post-resolve; empty = no token requested.
- **Server schema**: `permissions` removed from `GithubIntegrationLayer`
/ `GithubIntegrationSettings`. `deny_unknown_fields` rejects the stale
path.
- **Bundled `workflow.toml` parsing** (`run_manifest.rs`): now goes
through `SettingsLayer` via the new `parse_run_layer_from_settings_toml`
helper, so stale `[server.integrations.github.permissions]` errors
instead of being silently dropped by the old `toml::Table` lift-out.
- **Consumers updated**: server preflight, run launch path, and the CLI
worker (`runner.rs`) all read run-level permissions. CLI worker
previously hardcoded `HashMap::new()` — runs launched via the local CLI
path were getting no `GITHUB_TOKEN` regardless of TOML.
- **Shared helpers** on `RunIntegrationsGithubSettings`:
`is_token_requested()` and `resolve_permissions(lookup)` so server and
CLI don't drift.
- **OpenAPI + TS client** regenerated; new `RunIntegrationsSettings` /
`RunIntegrationsGithubSettings` schemas added, `permissions` removed
from `GithubIntegrationSettings`.
- **Repo workflows + docs** rewritten to the new path. Docs gain a
security-model note (boundary = installation grants; no Fabro-side cap).

## Key design decision: hand-rolled `Combine` for
`RunIntegrationsGithubLayer`

`ReplaceMap`'s "empty inherits from below" semantics (`maps.rs:76-80`)
are wrong here — we want `permissions = {}` in a higher layer to act as
an explicit clear. So the layer field is `Option<HashMap<...>>` with
hand-rolled `Combine`:

| Higher layer | Lower layer | Result |
|---|---|---|
| `None` | anything | lower (inherit) |
| `Some(map)` | anything | `Some(map)` (full replace, including
`Some({})` = clear) |

Not derived: the blanket `Option<T: Combine>` impl would recurse into
the inner `HashMap` and reintroduce empty-fallback. Documented inline in
`layers/run.rs`.

`InterpString` is preserved through resolve and only flattened to
`String` at the start-services boundary, matching the existing pattern.

### Plan Summary

- New `[run.integrations.github.permissions]` layer + resolved types;
remove from server side.
- Hand-rolled `Combine` so empty-wins-as-clear; no change to
`ReplaceMap` semantics for other consumers.
- Strict `SettingsLayer` parse for bundled `workflow.toml` so stale
schema errors loudly.
- Both server and CLI worker paths read run-level permissions via shared
helpers.
- OpenAPI + TS client regenerated; parity test added.
- Repo workflow TOMLs and `integrations/github.mdx` rewritten.


### Fabro Details

<details>
<summary>Ran 0 stages in 61m 23s for $53.41</summary>

| Stage | Duration | Cost | Retries |
|---|---|---|---|
| **Total** | **61m 23s** | **$53.41** | **0** |

</details>

<details>
<summary>Ran <code>ImplementPlan.fabro</code> (12 nodes and 15
edges)</summary>

```dot
digraph ImplementPlan {
    graph [
        goal="Implement and simplify",
        model_stylesheet="
            * { model: claude-opus-4-7; }
        "
    ]
    rankdir=LR

    start [shape=Mdiamond, label="Start"]
    exit  [shape=Msquare, label="Exit"]

    toolchain         [label="Toolchain", shape=parallelogram, script="command -v cargo >/dev/null || { curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y && sudo ln -sf $HOME/.cargo/bin/* /usr/local/bin/; }; cargo --version 2>&1", max_retries=0]
    preflight_compile [label="Preflight Compile", shape=parallelogram, script="cargo check -q --workspace 2>&1", max_retries=0]
    preflight_lint    [label="Preflight Lint", shape=parallelogram, script="cargo +nightly-2026-04-14 clippy -q --workspace --all-targets -- -D warnings 2>&1", max_retries=0]
    fix_lints         [label="Fix Lints", prompt="The preflight lint step failed. Read the build output from context and fix all clippy lint warnings.", max_visits=3]
    implement         [label="Implement", prompt="Read the plan file referenced in the goal and implement every step. Make all the code changes described in the plan. Use red/green TDD."]
    simplify_opus     [label="Simplify (Opus)", prompt="@prompts/simplify.md"]
    simplify_gpt      [label="Simplify (GPT-55)", prompt="@prompts/simplify.md", model="gpt-55"]
    verify            [label="Verify", shape=parallelogram, script="cargo +nightly-2026-04-14 clippy -q --workspace --all-targets -- -D warnings 2>&1 && cargo nextest run --cargo-quiet --workspace --status-level fail 2>&1 && cargo dev docs refresh 2>&1 && cargo dev docs check 2>&1", goal_gate=true, retry_target="fixup"]
    fixup             [label="Fixup", prompt="The verify step failed. Read the build output from context and fix all clippy lint warnings, test failures, and generated docs errors.", max_visits=3]
    fmt               [label="Format", shape=parallelogram, script="cargo +nightly-2026-04-14 fmt --all 2>&1", max_retries=0]

    start -> toolchain
    toolchain -> preflight_compile [condition="outcome=succeeded"]
    toolchain -> exit
    preflight_compile -> preflight_lint [condition="outcome=succeeded"]
    preflight_compile -> exit
    preflight_lint -> implement [condition="outcome=succeeded"]
    preflight_lint -> fix_lints
    fix_lints -> preflight_lint
    implement -> simplify_opus -> simplify_gpt -> verify
    verify -> fmt   [condition="outcome=succeeded"]
    verify -> fixup
    fixup -> verify
    fmt -> exit
}

```

</details>

⚒️ Generated with [Fabro](https://fabro.sh)

---------

Co-authored-by: Fabro <noreply@fabro.sh>
Co-authored-by: Bryan Helmkamp <bryan@brynary.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-05 15:33:31 -04:00
..
archive.rs chore(test): extract TestContext::set_http_target helper 2026-04-30 10:11:47 -04:00
artifact_cp.rs test(cli): trim slow integration fixture setup 2026-04-28 19:14:56 -07:00
artifact_list.rs test(cli): trim slow integration fixture setup 2026-04-28 19:14:56 -07:00
attach.rs Move GitHub token permissions to [run.integrations.github.permissions] (#215) 2026-05-05 15:33:31 -04:00
auth.rs test(cli): tighten env-dev-token-ignore tests 2026-05-01 16:25:13 -04:00
config.rs migrate cli install tests off sparse settings layers 2026-04-23 18:37:37 -04:00
create.rs chore(test): extract TestContext::set_http_target helper 2026-04-30 10:11:47 -04:00
diff.rs test(cli): prune slow integration outliers 2026-04-28 19:26:27 -07:00
discord.rs refactor(cli): deglobalize server and storage target flags 2026-04-05 16:06:42 -04:00
docs.rs refactor(cli): deglobalize server and storage target flags 2026-04-05 16:06:42 -04:00
doctor.rs chore(clippy): require reasons on allow attributes 2026-04-19 20:24:24 -04:00
dump.rs Surface silent fallback warnings in runs and logs (#205) 2026-05-05 09:18:05 -04:00
exec.rs chore(test): extract TestContext::set_http_target helper 2026-04-30 10:11:47 -04:00
fabro.rs feat(cli): rename store dump to dump 2026-04-23 07:48:03 -04:00
fork.rs test(cli): trim slow integration fixture setup 2026-04-28 19:14:56 -07:00
graph.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00
inspect.rs feat(run): separate stage state and artifact retries 2026-05-01 20:10:47 -04:00
install.rs fix(install): reject wildcard public URLs 2026-04-25 18:58:00 -04:00
json_global.rs fix(cli): remove dev-token env auth override 2026-05-01 15:04:01 -04:00
logs.rs Unify run event principals 2026-05-01 21:56:47 -04:00
mod.rs remove(cli): drop pr list command entirely 2026-04-24 08:56:07 -04:00
model.rs chore(catalog): add GPT-5.5 and GPT-5.5 Pro, set 5.5 as OpenAI default 2026-05-04 11:12:40 -04:00
model_list.rs refactor(cli): separate local socket and storage defaults 2026-04-06 11:57:14 -04:00
model_test.rs Model Test Bounded Concurrency Implementation Plan (#204) 2026-05-04 13:46:44 -04:00
parse.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00
pr.rs remove(cli): drop pr list command entirely 2026-04-24 08:56:07 -04:00
pr_close.rs refactor(pr): simplify server-side PR plumbing 2026-04-24 11:17:01 -04:00
pr_create.rs refactor(types): remove stage status compatibility 2026-04-30 06:48:47 -04:00
pr_merge.rs refactor(pr): simplify server-side PR plumbing 2026-04-24 11:17:01 -04:00
pr_view.rs test(cli): trim slow integration fixture setup 2026-04-28 19:14:56 -07:00
preflight.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00
provider.rs refactor(cli): deglobalize server and storage target flags 2026-04-05 16:06:42 -04:00
provider_login.rs Complete provider credential auth and scripted install 2026-04-13 09:15:45 -04:00
ps.rs test(cli): tighten env-dev-token-ignore tests 2026-05-01 16:25:13 -04:00
render_graph.rs lint(clippy): disallow blocking std::io and std::net on Tokio paths 2026-04-19 16:06:02 -04:00
repo.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00
repo_deinit.rs refactor(config): move project state under .fabro 2026-04-11 12:55:46 -04:00
repo_init.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00
resume.rs test(cli): prune slow integration outliers 2026-04-28 19:26:27 -07:00
rewind.rs test(cli): trim slow integration fixture setup 2026-04-28 19:14:56 -07:00
rm.rs chore(test): extract TestContext::set_http_target helper 2026-04-30 10:11:47 -04:00
run.rs Surface silent fallback warnings in runs and logs (#205) 2026-05-05 09:18:05 -04:00
runner.rs fix(test): align worker token fixtures with auth routing 2026-05-02 12:08:00 -04:00
sandbox_cp.rs test(cli): trim slow integration fixture setup 2026-04-28 19:14:56 -07:00
sandbox_preview.rs Make git metadata sandbox-native 2026-04-27 21:43:15 -07:00
sandbox_ssh.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00
secret.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00
secret_list.rs feat: add typed secrets metadata and API 2026-04-12 12:47:08 -04:00
secret_rm.rs refactor(cli): deglobalize server and storage target flags 2026-04-05 16:06:42 -04:00
secret_set.rs test(cli): align stale CI snapshots 2026-04-24 19:53:02 -04:00
send_analytics.rs refactor(cli): deglobalize server and storage target flags 2026-04-05 16:06:42 -04:00
send_panic.rs refactor(cli): deglobalize server and storage target flags 2026-04-05 16:06:42 -04:00
server_start.rs test(cli): trim slow integration fixture setup 2026-04-28 19:14:56 -07:00
server_status.rs refactor(server): unify daemon runtime metadata 2026-04-22 16:07:52 -04:00
server_stop.rs refactor(test): promote shared server-lifecycle test helpers into fabro-test 2026-04-19 16:43:26 -04:00
start.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00
support.rs Merge remote-tracking branch 'origin/main' 2026-05-02 10:06:25 -04:00
system.rs feat(system): add server-backed system commands 2026-04-06 16:10:06 -04:00
system_df.rs test(cli): trim slow integration fixture setup 2026-04-28 19:14:56 -07:00
system_events.rs refactor(cli): finish command context cleanup 2026-04-23 07:14:32 -04:00
system_info.rs refactor(cli): finish command context cleanup 2026-04-23 07:14:32 -04:00
system_prune.rs test(cli): trim slow integration fixture setup 2026-04-28 19:14:56 -07:00
test_panic.rs test: speed up slow default-profile tests and tighten nextest thresholds 2026-04-05 13:15:59 -04:00
top_level.rs feat(cli): show curated landing output for bare fabro 2026-04-17 08:59:03 -04:00
unarchive.rs chore(test): extract TestContext::set_http_target helper 2026-04-30 10:11:47 -04:00
uninstall.rs refactor(server): unify daemon runtime metadata 2026-04-22 16:07:52 -04:00
upgrade.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00
validate.rs fix(cli): keep validate off runtime preflight 2026-04-28 14:50:04 -07:00
version.rs feat(cli): add fabro version command 2026-04-14 16:30:53 -04:00
wait.rs test(cli): trim slow integration fixture setup 2026-04-28 19:14:56 -07:00
worker_auth.rs fix(test): align worker token fixtures with auth routing 2026-05-02 12:08:00 -04:00
workflow.rs test(cli): refresh list output expectations 2026-04-14 11:30:34 -04:00
workflow_create.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00
workflow_list.rs feat(cli): render fatal errors with miette 2026-04-24 15:35:57 -04:00