fix(ci): give the @claude mention workflow a usable GitHub token - #182

Open
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token
Open

fix(ci): give the @claude mention workflow a usable GitHub token#182
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token

Conversation

@MaryWylde

Copy link
Copy Markdown
Contributor

The job supplied neither github_token nor id-token: write, so claude-code-action fell back to minting a token over OIDC and failed all three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".

Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this repo, which avoids depending on the Claude GitHub App being installed on the org. Comment permissions go read -> write so Claude can post replies.

The job supplied neither `github_token` nor `id-token: write`, so
claude-code-action fell back to minting a token over OIDC and failed all
three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".
Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this
repo, which avoids depending on the Claude GitHub App being installed on
the org. Comment permissions go read -> write so Claude can post replies.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@github-actions

github-actionsBot commented Aug 19, 2026

Copy link
Copy Markdown

Claude finished @MaryWylde's task in 1m 19s —— View job


Review: fix(ci): give the @claude mention workflow a usable GitHub token

  • Gather context (read diff, compared with claude-code-review.yml)
  • Understand the request (review the CI token fix)
  • Review correctness/security of workflow change
  • Post final review

Summary

The core fix is correct: passing github_token: ${{ secrets.GITHUB_TOKEN }} matches the working pattern in claude-code-review.yml and avoids the OIDC minting path that was failing with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL". Good diagnosis, and the added comments explain the why well for future readers.

The pull-requests/issues permission bump from readwrite is correctly scoped — Claude needs to write comments/replies, and this doesn't touch contents, so it doesn't broaden write access to the repo itself.

The existing author_association gating (lines 38–50, unchanged by this PR) is sound and untouched — no regression there.

One thing worth confirming before merge

contents permission (line 56) stays read. That's fine if this workflow is meant to be review/answer-only. But unlike claude-code-review.yml (which never pushes), this mention workflow's own trigger prompt explicitly supports implementation requests and instructs pushing via git-push.sh origin HEAD using this same token. git push with the default GITHUB_TOKEN needs contents: write — with read, implementation-type @claude mentions will still fail, just later (at push time, 403) instead of at token-mint time. Left an inline comment with details.

If the intent is genuinely review/Q&A only for this trigger, this is a non-issue — otherwise contents: write is likely needed too.

@@ -54,8 +54,10 @@ jobs:
timeout-minutes: 15
permissions:
contents: read

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

contents stays read here while pull-requests/issues go to write. That's enough for Claude to comment, but this workflow (unlike claude-code-review.yml, which never pushes) is the one that handles implementation requests — the task prompt driving @claude on PRs explicitly instructs pushing via git-push.sh origin HEAD using this same github_token.

git push over the default GITHUB_TOKEN needs contents: write; with contents: read that push will get a 403, so "straightforward"/"complex" implementation requests (as opposed to reviews/Q&A) will still fail after this fix, just later in the flow (at push time instead of at token-mint time).

Worth confirming intentional — if this workflow is meant to stay review/answer-only, fine as is; if it's meant to implement and push (per its own trigger prompt), contents needs to be write too.

Fix this →

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MaryWylde
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(ci): give the @claude mention workflow a usable GitHub token - #182

Open
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token
Open

fix(ci): give the @claude mention workflow a usable GitHub token#182
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token

Conversation

@MaryWylde

Copy link
Copy Markdown
Contributor

The job supplied neither github_token nor id-token: write, so claude-code-action fell back to minting a token over OIDC and failed all three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".

Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this repo, which avoids depending on the Claude GitHub App being installed on the org. Comment permissions go read -> write so Claude can post replies.

The job supplied neither `github_token` nor `id-token: write`, so
claude-code-action fell back to minting a token over OIDC and failed all
three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".
Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this
repo, which avoids depending on the Claude GitHub App being installed on
the org. Comment permissions go read -> write so Claude can post replies.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@github-actions

github-actionsBot commented Aug 19, 2026

Copy link
Copy Markdown

Claude finished @MaryWylde's task in 1m 19s —— View job


Review: fix(ci): give the @claude mention workflow a usable GitHub token

  • Gather context (read diff, compared with claude-code-review.yml)
  • Understand the request (review the CI token fix)
  • Review correctness/security of workflow change
  • Post final review

Summary

The core fix is correct: passing github_token: ${{ secrets.GITHUB_TOKEN }} matches the working pattern in claude-code-review.yml and avoids the OIDC minting path that was failing with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL". Good diagnosis, and the added comments explain the why well for future readers.

The pull-requests/issues permission bump from readwrite is correctly scoped — Claude needs to write comments/replies, and this doesn't touch contents, so it doesn't broaden write access to the repo itself.

The existing author_association gating (lines 38–50, unchanged by this PR) is sound and untouched — no regression there.

One thing worth confirming before merge

contents permission (line 56) stays read. That's fine if this workflow is meant to be review/answer-only. But unlike claude-code-review.yml (which never pushes), this mention workflow's own trigger prompt explicitly supports implementation requests and instructs pushing via git-push.sh origin HEAD using this same token. git push with the default GITHUB_TOKEN needs contents: write — with read, implementation-type @claude mentions will still fail, just later (at push time, 403) instead of at token-mint time. Left an inline comment with details.

If the intent is genuinely review/Q&A only for this trigger, this is a non-issue — otherwise contents: write is likely needed too.

@@ -54,8 +54,10 @@ jobs:
timeout-minutes: 15
permissions:
contents: read

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

contents stays read here while pull-requests/issues go to write. That's enough for Claude to comment, but this workflow (unlike claude-code-review.yml, which never pushes) is the one that handles implementation requests — the task prompt driving @claude on PRs explicitly instructs pushing via git-push.sh origin HEAD using this same github_token.

git push over the default GITHUB_TOKEN needs contents: write; with contents: read that push will get a 403, so "straightforward"/"complex" implementation requests (as opposed to reviews/Q&A) will still fail after this fix, just later in the flow (at push time instead of at token-mint time).

Worth confirming intentional — if this workflow is meant to stay review/answer-only, fine as is; if it's meant to implement and push (per its own trigger prompt), contents needs to be write too.

Fix this →

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MaryWylde
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(ci): give the @claude mention workflow a usable GitHub token - #182

Open
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token
Open

fix(ci): give the @claude mention workflow a usable GitHub token#182
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token

Conversation

@MaryWylde

Copy link
Copy Markdown
Contributor

The job supplied neither github_token nor id-token: write, so claude-code-action fell back to minting a token over OIDC and failed all three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".

Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this repo, which avoids depending on the Claude GitHub App being installed on the org. Comment permissions go read -> write so Claude can post replies.

The job supplied neither `github_token` nor `id-token: write`, so
claude-code-action fell back to minting a token over OIDC and failed all
three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".
Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this
repo, which avoids depending on the Claude GitHub App being installed on
the org. Comment permissions go read -> write so Claude can post replies.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@github-actions

github-actionsBot commented Aug 19, 2026

Copy link
Copy Markdown

Claude finished @MaryWylde's task in 1m 19s —— View job


Review: fix(ci): give the @claude mention workflow a usable GitHub token

  • Gather context (read diff, compared with claude-code-review.yml)
  • Understand the request (review the CI token fix)
  • Review correctness/security of workflow change
  • Post final review

Summary

The core fix is correct: passing github_token: ${{ secrets.GITHUB_TOKEN }} matches the working pattern in claude-code-review.yml and avoids the OIDC minting path that was failing with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL". Good diagnosis, and the added comments explain the why well for future readers.

The pull-requests/issues permission bump from readwrite is correctly scoped — Claude needs to write comments/replies, and this doesn't touch contents, so it doesn't broaden write access to the repo itself.

The existing author_association gating (lines 38–50, unchanged by this PR) is sound and untouched — no regression there.

One thing worth confirming before merge

contents permission (line 56) stays read. That's fine if this workflow is meant to be review/answer-only. But unlike claude-code-review.yml (which never pushes), this mention workflow's own trigger prompt explicitly supports implementation requests and instructs pushing via git-push.sh origin HEAD using this same token. git push with the default GITHUB_TOKEN needs contents: write — with read, implementation-type @claude mentions will still fail, just later (at push time, 403) instead of at token-mint time. Left an inline comment with details.

If the intent is genuinely review/Q&A only for this trigger, this is a non-issue — otherwise contents: write is likely needed too.

@@ -54,8 +54,10 @@ jobs:
timeout-minutes: 15
permissions:
contents: read

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

contents stays read here while pull-requests/issues go to write. That's enough for Claude to comment, but this workflow (unlike claude-code-review.yml, which never pushes) is the one that handles implementation requests — the task prompt driving @claude on PRs explicitly instructs pushing via git-push.sh origin HEAD using this same github_token.

git push over the default GITHUB_TOKEN needs contents: write; with contents: read that push will get a 403, so "straightforward"/"complex" implementation requests (as opposed to reviews/Q&A) will still fail after this fix, just later in the flow (at push time instead of at token-mint time).

Worth confirming intentional — if this workflow is meant to stay review/answer-only, fine as is; if it's meant to implement and push (per its own trigger prompt), contents needs to be write too.

Fix this →

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MaryWylde
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(ci): give the @claude mention workflow a usable GitHub token - #182

Open
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token
Open

fix(ci): give the @claude mention workflow a usable GitHub token#182
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token

Conversation

@MaryWylde

Copy link
Copy Markdown
Contributor

The job supplied neither github_token nor id-token: write, so claude-code-action fell back to minting a token over OIDC and failed all three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".

Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this repo, which avoids depending on the Claude GitHub App being installed on the org. Comment permissions go read -> write so Claude can post replies.

The job supplied neither `github_token` nor `id-token: write`, so
claude-code-action fell back to minting a token over OIDC and failed all
three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".
Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this
repo, which avoids depending on the Claude GitHub App being installed on
the org. Comment permissions go read -> write so Claude can post replies.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@github-actions

github-actionsBot commented Aug 19, 2026

Copy link
Copy Markdown

Claude finished @MaryWylde's task in 1m 19s —— View job


Review: fix(ci): give the @claude mention workflow a usable GitHub token

  • Gather context (read diff, compared with claude-code-review.yml)
  • Understand the request (review the CI token fix)
  • Review correctness/security of workflow change
  • Post final review

Summary

The core fix is correct: passing github_token: ${{ secrets.GITHUB_TOKEN }} matches the working pattern in claude-code-review.yml and avoids the OIDC minting path that was failing with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL". Good diagnosis, and the added comments explain the why well for future readers.

The pull-requests/issues permission bump from readwrite is correctly scoped — Claude needs to write comments/replies, and this doesn't touch contents, so it doesn't broaden write access to the repo itself.

The existing author_association gating (lines 38–50, unchanged by this PR) is sound and untouched — no regression there.

One thing worth confirming before merge

contents permission (line 56) stays read. That's fine if this workflow is meant to be review/answer-only. But unlike claude-code-review.yml (which never pushes), this mention workflow's own trigger prompt explicitly supports implementation requests and instructs pushing via git-push.sh origin HEAD using this same token. git push with the default GITHUB_TOKEN needs contents: write — with read, implementation-type @claude mentions will still fail, just later (at push time, 403) instead of at token-mint time. Left an inline comment with details.

If the intent is genuinely review/Q&A only for this trigger, this is a non-issue — otherwise contents: write is likely needed too.

@@ -54,8 +54,10 @@ jobs:
timeout-minutes: 15
permissions:
contents: read

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

contents stays read here while pull-requests/issues go to write. That's enough for Claude to comment, but this workflow (unlike claude-code-review.yml, which never pushes) is the one that handles implementation requests — the task prompt driving @claude on PRs explicitly instructs pushing via git-push.sh origin HEAD using this same github_token.

git push over the default GITHUB_TOKEN needs contents: write; with contents: read that push will get a 403, so "straightforward"/"complex" implementation requests (as opposed to reviews/Q&A) will still fail after this fix, just later in the flow (at push time instead of at token-mint time).

Worth confirming intentional — if this workflow is meant to stay review/answer-only, fine as is; if it's meant to implement and push (per its own trigger prompt), contents needs to be write too.

Fix this →

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MaryWylde
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(ci): give the @claude mention workflow a usable GitHub token - #182

Open
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token
Open

fix(ci): give the @claude mention workflow a usable GitHub token#182
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token

Conversation

@MaryWylde

Copy link
Copy Markdown
Contributor

The job supplied neither github_token nor id-token: write, so claude-code-action fell back to minting a token over OIDC and failed all three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".

Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this repo, which avoids depending on the Claude GitHub App being installed on the org. Comment permissions go read -> write so Claude can post replies.

The job supplied neither `github_token` nor `id-token: write`, so
claude-code-action fell back to minting a token over OIDC and failed all
three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".
Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this
repo, which avoids depending on the Claude GitHub App being installed on
the org. Comment permissions go read -> write so Claude can post replies.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@github-actions

github-actionsBot commented Aug 19, 2026

Copy link
Copy Markdown

Claude finished @MaryWylde's task in 1m 19s —— View job


Review: fix(ci): give the @claude mention workflow a usable GitHub token

  • Gather context (read diff, compared with claude-code-review.yml)
  • Understand the request (review the CI token fix)
  • Review correctness/security of workflow change
  • Post final review

Summary

The core fix is correct: passing github_token: ${{ secrets.GITHUB_TOKEN }} matches the working pattern in claude-code-review.yml and avoids the OIDC minting path that was failing with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL". Good diagnosis, and the added comments explain the why well for future readers.

The pull-requests/issues permission bump from readwrite is correctly scoped — Claude needs to write comments/replies, and this doesn't touch contents, so it doesn't broaden write access to the repo itself.

The existing author_association gating (lines 38–50, unchanged by this PR) is sound and untouched — no regression there.

One thing worth confirming before merge

contents permission (line 56) stays read. That's fine if this workflow is meant to be review/answer-only. But unlike claude-code-review.yml (which never pushes), this mention workflow's own trigger prompt explicitly supports implementation requests and instructs pushing via git-push.sh origin HEAD using this same token. git push with the default GITHUB_TOKEN needs contents: write — with read, implementation-type @claude mentions will still fail, just later (at push time, 403) instead of at token-mint time. Left an inline comment with details.

If the intent is genuinely review/Q&A only for this trigger, this is a non-issue — otherwise contents: write is likely needed too.

@@ -54,8 +54,10 @@ jobs:
timeout-minutes: 15
permissions:
contents: read

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

contents stays read here while pull-requests/issues go to write. That's enough for Claude to comment, but this workflow (unlike claude-code-review.yml, which never pushes) is the one that handles implementation requests — the task prompt driving @claude on PRs explicitly instructs pushing via git-push.sh origin HEAD using this same github_token.

git push over the default GITHUB_TOKEN needs contents: write; with contents: read that push will get a 403, so "straightforward"/"complex" implementation requests (as opposed to reviews/Q&A) will still fail after this fix, just later in the flow (at push time instead of at token-mint time).

Worth confirming intentional — if this workflow is meant to stay review/answer-only, fine as is; if it's meant to implement and push (per its own trigger prompt), contents needs to be write too.

Fix this →

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MaryWylde
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(ci): give the @claude mention workflow a usable GitHub token - #182

Open
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token
Open

fix(ci): give the @claude mention workflow a usable GitHub token#182
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token

Conversation

@MaryWylde

Copy link
Copy Markdown
Contributor

The job supplied neither github_token nor id-token: write, so claude-code-action fell back to minting a token over OIDC and failed all three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".

Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this repo, which avoids depending on the Claude GitHub App being installed on the org. Comment permissions go read -> write so Claude can post replies.

The job supplied neither `github_token` nor `id-token: write`, so
claude-code-action fell back to minting a token over OIDC and failed all
three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".
Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this
repo, which avoids depending on the Claude GitHub App being installed on
the org. Comment permissions go read -> write so Claude can post replies.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@github-actions

github-actionsBot commented Aug 19, 2026

Copy link
Copy Markdown

Claude finished @MaryWylde's task in 1m 19s —— View job


Review: fix(ci): give the @claude mention workflow a usable GitHub token

  • Gather context (read diff, compared with claude-code-review.yml)
  • Understand the request (review the CI token fix)
  • Review correctness/security of workflow change
  • Post final review

Summary

The core fix is correct: passing github_token: ${{ secrets.GITHUB_TOKEN }} matches the working pattern in claude-code-review.yml and avoids the OIDC minting path that was failing with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL". Good diagnosis, and the added comments explain the why well for future readers.

The pull-requests/issues permission bump from readwrite is correctly scoped — Claude needs to write comments/replies, and this doesn't touch contents, so it doesn't broaden write access to the repo itself.

The existing author_association gating (lines 38–50, unchanged by this PR) is sound and untouched — no regression there.

One thing worth confirming before merge

contents permission (line 56) stays read. That's fine if this workflow is meant to be review/answer-only. But unlike claude-code-review.yml (which never pushes), this mention workflow's own trigger prompt explicitly supports implementation requests and instructs pushing via git-push.sh origin HEAD using this same token. git push with the default GITHUB_TOKEN needs contents: write — with read, implementation-type @claude mentions will still fail, just later (at push time, 403) instead of at token-mint time. Left an inline comment with details.

If the intent is genuinely review/Q&A only for this trigger, this is a non-issue — otherwise contents: write is likely needed too.

@@ -54,8 +54,10 @@ jobs:
timeout-minutes: 15
permissions:
contents: read

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

contents stays read here while pull-requests/issues go to write. That's enough for Claude to comment, but this workflow (unlike claude-code-review.yml, which never pushes) is the one that handles implementation requests — the task prompt driving @claude on PRs explicitly instructs pushing via git-push.sh origin HEAD using this same github_token.

git push over the default GITHUB_TOKEN needs contents: write; with contents: read that push will get a 403, so "straightforward"/"complex" implementation requests (as opposed to reviews/Q&A) will still fail after this fix, just later in the flow (at push time instead of at token-mint time).

Worth confirming intentional — if this workflow is meant to stay review/answer-only, fine as is; if it's meant to implement and push (per its own trigger prompt), contents needs to be write too.

Fix this →

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MaryWylde
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(ci): give the @claude mention workflow a usable GitHub token - #182

Open
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token
Open

fix(ci): give the @claude mention workflow a usable GitHub token#182
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token

Conversation

@MaryWylde

Copy link
Copy Markdown
Contributor

The job supplied neither github_token nor id-token: write, so claude-code-action fell back to minting a token over OIDC and failed all three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".

Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this repo, which avoids depending on the Claude GitHub App being installed on the org. Comment permissions go read -> write so Claude can post replies.

The job supplied neither `github_token` nor `id-token: write`, so
claude-code-action fell back to minting a token over OIDC and failed all
three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".
Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this
repo, which avoids depending on the Claude GitHub App being installed on
the org. Comment permissions go read -> write so Claude can post replies.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@github-actions

github-actionsBot commented Aug 19, 2026

Copy link
Copy Markdown

Claude finished @MaryWylde's task in 1m 19s —— View job


Review: fix(ci): give the @claude mention workflow a usable GitHub token

  • Gather context (read diff, compared with claude-code-review.yml)
  • Understand the request (review the CI token fix)
  • Review correctness/security of workflow change
  • Post final review

Summary

The core fix is correct: passing github_token: ${{ secrets.GITHUB_TOKEN }} matches the working pattern in claude-code-review.yml and avoids the OIDC minting path that was failing with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL". Good diagnosis, and the added comments explain the why well for future readers.

The pull-requests/issues permission bump from readwrite is correctly scoped — Claude needs to write comments/replies, and this doesn't touch contents, so it doesn't broaden write access to the repo itself.

The existing author_association gating (lines 38–50, unchanged by this PR) is sound and untouched — no regression there.

One thing worth confirming before merge

contents permission (line 56) stays read. That's fine if this workflow is meant to be review/answer-only. But unlike claude-code-review.yml (which never pushes), this mention workflow's own trigger prompt explicitly supports implementation requests and instructs pushing via git-push.sh origin HEAD using this same token. git push with the default GITHUB_TOKEN needs contents: write — with read, implementation-type @claude mentions will still fail, just later (at push time, 403) instead of at token-mint time. Left an inline comment with details.

If the intent is genuinely review/Q&A only for this trigger, this is a non-issue — otherwise contents: write is likely needed too.

@@ -54,8 +54,10 @@ jobs:
timeout-minutes: 15
permissions:
contents: read

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

contents stays read here while pull-requests/issues go to write. That's enough for Claude to comment, but this workflow (unlike claude-code-review.yml, which never pushes) is the one that handles implementation requests — the task prompt driving @claude on PRs explicitly instructs pushing via git-push.sh origin HEAD using this same github_token.

git push over the default GITHUB_TOKEN needs contents: write; with contents: read that push will get a 403, so "straightforward"/"complex" implementation requests (as opposed to reviews/Q&A) will still fail after this fix, just later in the flow (at push time instead of at token-mint time).

Worth confirming intentional — if this workflow is meant to stay review/answer-only, fine as is; if it's meant to implement and push (per its own trigger prompt), contents needs to be write too.

Fix this →

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MaryWylde
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(ci): give the @claude mention workflow a usable GitHub token - #182

Open
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token
Open

fix(ci): give the @claude mention workflow a usable GitHub token#182
MaryWylde wants to merge 1 commit into
devfrom
fix/claude-mention-workflow-token

Conversation

@MaryWylde

Copy link
Copy Markdown
Contributor

The job supplied neither github_token nor id-token: write, so claude-code-action fell back to minting a token over OIDC and failed all three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".

Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this repo, which avoids depending on the Claude GitHub App being installed on the org. Comment permissions go read -> write so Claude can post replies.

The job supplied neither `github_token` nor `id-token: write`, so
claude-code-action fell back to minting a token over OIDC and failed all
three attempts with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL".
Use the run's own GITHUB_TOKEN, matching claude-code-review.yml in this
repo, which avoids depending on the Claude GitHub App being installed on
the org. Comment permissions go read -> write so Claude can post replies.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@github-actions

github-actionsBot commented Aug 19, 2026

Copy link
Copy Markdown

Claude finished @MaryWylde's task in 1m 19s —— View job


Review: fix(ci): give the @claude mention workflow a usable GitHub token

  • Gather context (read diff, compared with claude-code-review.yml)
  • Understand the request (review the CI token fix)
  • Review correctness/security of workflow change
  • Post final review

Summary

The core fix is correct: passing github_token: ${{ secrets.GITHUB_TOKEN }} matches the working pattern in claude-code-review.yml and avoids the OIDC minting path that was failing with "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL". Good diagnosis, and the added comments explain the why well for future readers.

The pull-requests/issues permission bump from readwrite is correctly scoped — Claude needs to write comments/replies, and this doesn't touch contents, so it doesn't broaden write access to the repo itself.

The existing author_association gating (lines 38–50, unchanged by this PR) is sound and untouched — no regression there.

One thing worth confirming before merge

contents permission (line 56) stays read. That's fine if this workflow is meant to be review/answer-only. But unlike claude-code-review.yml (which never pushes), this mention workflow's own trigger prompt explicitly supports implementation requests and instructs pushing via git-push.sh origin HEAD using this same token. git push with the default GITHUB_TOKEN needs contents: write — with read, implementation-type @claude mentions will still fail, just later (at push time, 403) instead of at token-mint time. Left an inline comment with details.

If the intent is genuinely review/Q&A only for this trigger, this is a non-issue — otherwise contents: write is likely needed too.

@@ -54,8 +54,10 @@ jobs:
timeout-minutes: 15
permissions:
contents: read

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

contents stays read here while pull-requests/issues go to write. That's enough for Claude to comment, but this workflow (unlike claude-code-review.yml, which never pushes) is the one that handles implementation requests — the task prompt driving @claude on PRs explicitly instructs pushing via git-push.sh origin HEAD using this same github_token.

git push over the default GITHUB_TOKEN needs contents: write; with contents: read that push will get a 403, so "straightforward"/"complex" implementation requests (as opposed to reviews/Q&A) will still fail after this fix, just later in the flow (at push time instead of at token-mint time).

Worth confirming intentional — if this workflow is meant to stay review/answer-only, fine as is; if it's meant to implement and push (per its own trigger prompt), contents needs to be write too.

Fix this →

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MaryWylde