mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 20:34:57 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Storybook previews help contributors review the board UI. > - The publishing workflow uses the default branch CODEOWNERS file to authorize users. > - Tonio and Scott need access to this workflow. > - This pull request adds both accounts as release documentation owners. > - The existing workflow can then authorize both accounts without a separate user list in code. ## Linked Issues or Issue Description **What existing behavior does this improve?** Access to the Storybook build and publishing workflow. **Subsystem affected** Repository ownership and GitHub Actions authorization. **Current behavior** The workflow reads individual accounts from every CODEOWNERS rule on the default branch. Neither `tonio-alucema` nor `scotttong` is in that file. Both accounts already have repository admin access, but the workflow authorization check denies them. **Proposed behavior** Add both accounts to the `doc/RELEASING.md` ownership rule. After merge, both can start and rerun Storybook publishing workflows. A configured `storybook-deploy` environment reviewer must still approve deployment. CODEOWNERS membership does not add an account to the environment reviewer settings. **Reason and benefit** Contributors can publish UI previews through the same CODEOWNERS policy as other maintainers. The authorization code has no account-specific exceptions. **Breaking changes** None. The existing authorization and deployment approval checks remain in place. **Additional context** Related changes: #13226 added the publishing workflow. #13231 added stable branch bookmarks. A search found no open PR for these permission changes. ## What Changed - Add `@tonio-alucema` and `@scotttong` only to the release documentation ownership rule. - Test that accounts listed for release documentation can start and rerun publishing workflows. - Test that removing an account from CODEOWNERS removes its publishing access. - Explain how CODEOWNERS entries and environment reviewers affect publishing access. ## Verification - `node --test scripts/__tests__/storybook-deploy.test.mjs`: all 25 tests pass. - `actionlint .github/workflows/storybook-deploy.yml .github/workflows/storybook-visual.yml`: passes. - `git diff --check`: passes. - GitHub API checks confirm that both accounts have repository admin access. The deployment environment requires an existing reviewer and disables administrator bypass. - Repository-wide typecheck, tests, and build were attempted. They cannot complete in this worktree because workspace dependencies are not installed. Typecheck cannot find Node type definitions. Tests and build cannot load the workspace `tsx` package. - After merge, run `Storybook Deploy` from `master`, select a source branch, obtain environment approval, and check the published URLs in the run summary. ## Risks Both accounts gain permission to start and rerun Storybook publishing. Deployment still needs approval from a configured environment reviewer. No AWS permissions or live GitHub settings change in this PR. ## Model Used OpenAI GPT-6 through Codex. The exact backend model ID and context window are not exposed in this session. The agent used reasoning, repository inspection, code editing, shell execution, and GitHub API tools. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>