fix(triage): gate OPENAI_API_KEY in reconsider workflow on AGENT_SHIN_ENABLED

The reconsider workflow was missed by the earlier OPENAI_API_KEY gating
commit. The PR/issue author counts as authorized to trigger reconsider,
so an external OSS contributor whose PR was bot-closed could comment
`@agent-shin reconsider` and force paid LLM calls before the team
flipped AGENT_SHIN_ENABLED to true.

Mirror the gate from triage_pr_with_llm.yml / triage_issue_with_llm.yml:
bind OPENAI_API_KEY to the empty string unless AGENT_SHIN_ENABLED is the
literal string 'true'. Reconsider has no workflow_dispatch trigger, so
AGENT_SHIN_ENABLED is the sole gate. The script short-circuits with
skip-no-llm-key when the key is empty, so dry-run rollout still works.
This commit is contained in:
mateo-berri 2026-05-19 08:24:35 +00:00
parent 7b366fede5
commit 7f69ae6755
No known key found for this signature in database

View file

@ -98,7 +98,16 @@ jobs:
if: steps.auth.outputs.authorized == 'true'
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
# Mirror the OPENAI_API_KEY gate used in triage_pr_with_llm.yml and
# triage_issue_with_llm.yml: only expose the LLM key when the bot
# has been opted in (AGENT_SHIN_ENABLED=true). Reconsider has no
# workflow_dispatch path, so AGENT_SHIN_ENABLED is the sole gate.
# Without this, an external OSS contributor whose PR was auto-closed
# could comment `@agent-shin reconsider` and trigger paid LLM calls
# before the team has set AGENT_SHIN_ENABLED — the authorization
# check alone is not enough, since the PR/issue author counts as
# "authorized" but is still an external contributor.
OPENAI_API_KEY: ${{ vars.AGENT_SHIN_ENABLED == 'true' && secrets.OPENAI_API_KEY || '' }}
OPENAI_BASE_URL: ${{ vars.OPENAI_BASE_URL }}
TRIAGE_MODEL: ${{ vars.TRIAGE_MODEL }}
AGENT_SHIN_ENABLED: ${{ vars.AGENT_SHIN_ENABLED }}