Repository navigation
feat(cli): allow uploads from forked pull requests, opted in explicitly - #1205
Merged
Merged
Conversation
A forked `pull_request` run gets no repository secrets, so it can present neither an org token nor (for a collection-first org) a public repo id. `--allow-forked-pr-uploads` / `TRUNK_ALLOW_FORKED_PR_UPLOADS` opts such a run into a lane authorized server-side by the test collection's own opt-in, using the `--test-collection-id` the workflow already passes. The flag is a mode selector, not a credential — it is sent as `x-trunk-allow-forked-pr-uploads: true` and grants nothing on its own. Requiring it is the point: without it, "no token" would silently become an anonymous upload, and because this lane fails open on authorization errors the misconfiguration would surface as a warning and a green CI step. A job whose `TRUNK_API_TOKEN` secret fails to interpolate still errors out. It also errors early when set without `--test-collection-id`: there would be nothing for the server to authorize against, and that failure is far clearer at arg-parse time than as a 401 the run then swallows. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
😎 Merged successfully - details. |
acatxnamedvirtue
marked this pull request as ready for review
September 22, 2026 15:38
Contributor
Author
|
@claude review please |
|
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #1205 +/- ##
==========================================
+ Coverage 83.70% 83.96% +0.25%
==========================================
Files 74 74
Lines 17667 17745 +78
==========================================
+ Hits 14789 14899 +110
+ Misses 2878 2846 -32 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
Contributor
Author
|
@claude review please |
acatxnamedvirtue
requested review from
TylerJang27,
dfrankland and
max-trunk
September 23, 2026 15:49
TylerJang27
approved these changes
Sep 24, 2026
TylerJang27
left a comment
Collaborator
There was a problem hiding this comment.
LGTM, reviewing the rest
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A forked
pull_requestrun gets no repository secrets, so it can present neither an org token nor — for a collection-first org — a public repo id.--allow-forked-pr-uploads/TRUNK_ALLOW_FORKED_PR_UPLOADSopts such a run into a lane authorized server-side by the test collection's own opt-in, using the--test-collection-idthe workflow already passes.Pairs with trunk-io/trunk#34002, which adds the server lane. That has to land and deploy first — until it does, a run using this flag gets a 401 (and, by this lane's fail-open rule, a warning and a green step).
The flag is a mode selector, not a credential
It is sent as
x-trunk-allow-forked-pr-uploads: true, grants nothing on its own, and anyone can send it. Requiring it is the point: without it, "no token" would silently become an anonymous upload attempt, and because this lane fails open on authorization errors, a job whoseTRUNK_API_TOKENsecret failed to interpolate would report success instead of failing. With the flag, that job still errors out exactly as it does today.It also errors early when set without
--test-collection-id— there would be nothing for the server to authorize against, and that reads far better at arg-parse time than as a 401 the run then swallows.Why no new identifier
The collection's short id is already public and already in the workflow (
--test-collection-id), so there is nothing to mint or paste. The trade, decided on the trunk2 side: it cannot be rotated, so the collection's toggle is the only revocation lever.Test plan
cargo check -p trunk-analytics-cli -p api -p constants -p test_reportcargo test -p api— 27/27, including two new tests: the header is sent with no credential present, and the flag satisfies the credential requirementcargo fmt --allcargo clippy— warning count in the touched files is identical tomain(6 before, 6 after), so nothing new was introduced🤖 Generated with Claude Code