Repository navigation
Conversation
…h protections When a GitHub branch needs a review the viewer cannot give (a code owner's, say), auto-merge has nothing it can ever finish waiting on, and the host may refuse to arm it at all. GitHub already lets administrators merge past those protections, which is what `gh pr merge --admin` does. Read GitHub's `viewerCanMergeAsAdmin` into a new `mergeAsAdmin` viewer permission, accept a `bypassRequirements` flag on merge actions that sends the direct `mergePullRequest` mutation instead of arming auto-merge or joining the merge queue, and offer it as a checkbox in the merge and auto-merge confirm dialogs for viewers GitHub says may use it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This PR adds a cross-layer GitHub administrator-merge workflow that can bypass required reviews, checks, and merge queues through a new destructive confirmation path. Although it is explicitly opt-in and permission-gated, the privileged and consequential production behavior requires human review. You can add or adjust custom eligibility rules. Learn more. |
relax |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (12)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe pull request adds GitHub administrator-merge permission data and a bypass option for merge actions. The server validates bypass requests and sends permitted requests as direct merges. The pull request dialog exposes the option when permission is available. ChangesAdministrator Merge Bypass
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant PullRequestDetailPanel
participant PullRequestService
participant GitHubPullRequestProvider
participant GitHubPullRequestApi
participant GitHub
PullRequestDetailPanel->>PullRequestService: runAction with bypassRequirements
PullRequestService->>GitHubPullRequestProvider: forward validated bypass request
GitHubPullRequestProvider->>GitHubPullRequestApi: runPullRequestAction with bypassRequirements
GitHubPullRequestApi->>GitHub: mergePullRequest mutation
Suggested reviewers: Merge Risk: ⚪ Minimal · up to This adds an opt-in administrator merge that is permission-gated on the server and shown in the dialog only to eligible viewers. No merge-blocking issue was found. A live admin merge against a protected repository has not been exercised. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The new operation can merge code without required reviews, checks or the merge queue. It requires an explicit choice and freshly checked administrator-merge permission. No unauthorized bypass was established, but concurrent branch changes and uncertain remote outcomes remain important limitations. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 3 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (3 passed)
Full details: Description checkExplanation The description covers the problem, implementation, scope, screenshots, and focused verification. However, the change introduces broader merge workflow behavior without linking a triaged issue or explicit maintainer approval, as required by the template.
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Problem
On a GitHub branch that needs a review the viewer can't give, such as a code owner's approval on their own PR, auto-merge never has anything it can finish waiting on. GitHub can also refuse to arm it at all, which shows up as "Could not turn on auto-merge: The host refused it…". The only way through is
gh pr merge --adminin a terminal, even when GitHub would let the viewer bypass the protections.Change
viewerCanMergeAsAdminwith the core detail and with the viewer-permissions check. Expose it as a newmergeAsAdminviewer permission. It is only set when GitHub saystrueand the viewer can write; absent means no.bypassRequirementstoPullRequestActionInput. Formergeandenable-auto-mergeit sends the directmergePullRequestmutation rather thanenablePullRequestAutoMerge, and skips the merge queue. That matchesgh pr merge --admin.PullRequestService.runActionrefuses the flag for stack merges, for any other action, and for viewers withoutmergeAsAdmin.docs/user/source-control.md.Mobile has no PR merge UI, so nothing changes there. Other hosts never set
mergeAsAdmin, so they never see the checkbox.Scope and approval
There is no prior issue or discussion for this. It reuses the existing merge and auto-merge actions and adds one GitHub-only option to them.
Screenshots
Before: turning on auto-merge on a branch that needs a code owner's review fails, and there's no way through from the app.
After: viewers GitHub lets bypass protections get a checkbox in the dialog. Ticking it turns the action into a direct admin merge. Captured on a real BLOCKED pull request; the dialog was cancelled each time.
Verification
vp test runpasses onGitHubPullRequestApi.test.ts,GitHubPullRequestProvider.test.ts,gitHubPullRequestJson.test.ts,PullRequestService.test.ts(450 tests) andpackages/contracts/src/pullRequest.test.ts. New tests cover:mergePullRequest, notenablePullRequestAutoMerge, for a BLOCKED branch and for a merge-queue branch.viewerCanMergeAsAdmindecodes only when true, and an unknown or missing value grants nothing.tsc --noEmitis clean for contracts, server and web. Lint on the changed files shows only warnings that already exist on main.viewerCanMergeAsAdmin: true. The checkbox appears and the dialog switches to the admin merge, as in the screenshots above.Opus 5.5 (1M context) via Claude Code in T3 Code.
🤖 Generated with Claude Code