From a6fff434a418159e242fa327841a9c3d5bb7947b Mon Sep 17 00:00:00 2001 From: saphid <4596216+saphid@users.noreply.github.com> Date: Mon, 28 Sep 2026 14:45:54 +1000 Subject: [PATCH] Website feedback: attribution first, escape <, wait out the fill timer; maintainers only in the approval queue Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/approve-contributor.yml | 9 ++++++--- site/lib/feedback.js | 23 ++++++++++++++--------- site/public/js/feedback.js | 6 ++++-- site/test/feedback.test.mjs | 8 +++++--- 4 files changed, 29 insertions(+), 17 deletions(-) diff --git a/.github/workflows/approve-contributor.yml b/.github/workflows/approve-contributor.yml index 665128b..68cc7fd 100644 --- a/.github/workflows/approve-contributor.yml +++ b/.github/workflows/approve-contributor.yml @@ -9,9 +9,12 @@ on: jobs: approve: - # Only comments that might approve someone join the queue, and they run one - # at a time so two lgtm replies can't race on APPROVED_CONTRIBUTORS. - if: contains(github.event.comment.body, 'lgtm') # contains() ignores case + # Only maintainers' comments that might approve someone join the queue, and + # they run one at a time so two lgtm replies can't race on APPROVED_CONTRIBUTORS. + # (The script below still checks for write access.) + if: >- + contains(github.event.comment.body, 'lgtm') && + contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.comment.author_association) concurrency: group: approve-contributor cancel-in-progress: false diff --git a/site/lib/feedback.js b/site/lib/feedback.js index 91df858..d697474 100644 --- a/site/lib/feedback.js +++ b/site/lib/feedback.js @@ -20,11 +20,13 @@ const oneLine = (value, max) => String(value ?? "").replace(/\s+/g, " ").trim(). // Mentions in someone else's text would ping strangers, and issue references // (#1, owner/repo#1, GH-1, github.com links) would add backlinks to other // people's issues, so break them all with a zero-width space. Escaping & first -// stops @ and # from turning back into @ and # when GitHub renders. +// stops @ and # from turning back into @ and # when GitHub renders, +// and escaping < keeps out raw HTML such as an unclosed