anthropics / anthropics/claude-code-action

Default actions installed by` /install-github-app` had too broad permissions

Abierto
#854 1 comentario 0 reacciones 0 asignados Ver en GitHub
area:installation area:permissions bug p1 provider:1p
Lenguaje dominante
TypeScript
Estrellas
8.9k
Forks
2.1k
Merge medio
3 d 9 h
PR fusionados (30 d)
10

Descripción

## Description

When I installed Claude Code Review and Claude workflows:

In `claude.yml`:

```yaml
if: |
(github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) ||
(github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
```

This job runs for any issue/PR comment containing @claude and does not check the commenter’s association or permissions. In a public repo (or any repo where outsiders can comment), that means any user can trigger runs that use `secrets.CLAUDE_CODE_OAUTH_TOKEN`, which can lead to unauthorized usage and unexpected cost.

## Reproduction Steps

Steps to reproduce the behavior:

Create a repo on Github, then go through the normal `/install-github-app` flow.

## Expected Behavior

We should consider gating on `github.event.comment.author_association` / `github.actor` or restricting to write-access members before invoking the action.

## Workflow yml file

Here is a corrected version:

```yaml
name: Claude Code

on:
issue_comment:
types: [created]
pull_request_review_comment:
types: [created]
issues:
types: [opened, assigned]
pull_request_review:
types: [submitted]

jobs:
claude:
# Only run for trusted users (MEMBER, OWNER, COLLABORATOR)
if: |
(github.event_name == 'issue_comment' &&
contains(fromJSON('["MEMBER", "OWNER", "COLLABORATOR"]'), github.event.comment.author_association) &&
contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review_comment' &&
contains(fromJSON('["MEMBER", "OWNER", "COLLABORATOR"]'), github.event.comment.author_association) &&
contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review' &&
contains(fromJSON('["MEMBER", "OWNER", "COLLABORATOR"]'), github.event.review.author_association) &&
contains(github.event.review.body, '@claude')) ||
(github.event_name == 'issues' &&
contains(fromJSON('["MEMBER", "OWNER", "COLLABORATOR"]'), github.event.issue.author_association) &&
(contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: read
issues: read
id-token: write
actions: read # Required for Claude to read CI results on PRs
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 1

- name: Run Claude Code
id: claude
uses: anthropics/claude-code-action@v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}

# This is an optional setting that allows Claude to read CI results on PRs
additional_permissions: |
actions: read

# Optional: Give a custom prompt to Claude. If this is not specified, Claude will perform the instructions specified in the comment that tagged it.
# prompt: 'Update the pull request description to include a summary of changes.'

# Optional: Add claude_args to customize behavior and configuration
# See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md
# or https://code.claude.com/docs/en/cli-reference for available options
# claude_args: '--allowed-tools Bash(gh pr:*)'

```

## API Provider

[x] Anthropic First-Party API (default)
[ ] AWS Bedrock
[ ] GCP Vertex

**Additional context**
Add any other context about the problem here.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.