Skip to content

Make Claude Code Review advisory so expired OAuth does not fail PRs - #87

Merged
mohabbis merged 1 commit into
mainfrom
cursor/advisory-claude-review-beb9
Aug 31, 2026
Merged

Make Claude Code Review advisory so expired OAuth does not fail PRs#87
mohabbis merged 1 commit into
mainfrom
cursor/advisory-claude-review-beb9

Conversation

@mohabbis

Copy link
Copy Markdown
Owner

Why this PR exists

#86 merged with a red Claude Code Review / claude-review check. CI / test was already green. This PR lands the repo-side fix so that check no longer fails PRs.

Root cause

Two stacked failures, both in anthropics/claude-code-action@v1:

  1. Bot actor (Cursor PRs). The action rejects non-human actors unless they are listed in allowed_bots. Cursor Cloud Agents open/push as cursor[bot], so the job died immediately with Workflow initiated by non-human actor: cursor.

  2. Expired or quota-exhausted OAuth (every PR since 2026-07-15). After the actor check, the SDK returns subtype: success with is_error: true, num_turns: 1, and total_cost_usd: 0 — it never calls the model. The same envelope appears on human-authored PRs. Full output is hidden; this matches Anthropic issues where CLAUDE_CODE_OAUTH_TOKEN is a 401 or a 429. That secret cannot be rotated from this PR.

Fix

  • allowed_bots: cursor,cursor[bot] so Cursor-opened PRs can run the review.
  • continue-on-error: true on the review step, plus a warning annotation when it fails. Review stays wired so a rotated token starts posting again; it no longer fails the check.
  • AGENTS.md / CLAUDE.md note the workflow is advisory.

To restore actual review comments, re-mint the token locally with claude setup-token and update the CLAUDE_CODE_OAUTH_TOKEN repo secret.

Open in Web Open in Cursor 

The review action has returned is_error:true at $0 cost on every PR since
2026-07-15 (CLAUDE_CODE_OAUTH_TOKEN rejected or quota exhausted). Keep the
job, allow cursor[bot], and continue-on-error so a rotated secret resumes
reviews without blocking CI.

Co-authored-by: Muhammad Rafiq <mohabbis@users.noreply.github.com>
@vercel

vercel Bot commented Aug 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lumen-idpz Ready Ready Preview Aug 31, 2026 6:08pm

Request Review

@mohabbis
mohabbis marked this pull request as ready for review August 31, 2026 18:10
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 31, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-08-31T18:11:59.406801Z 0d6414e Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@mohabbis
mohabbis merged commit 5a4446d into main Aug 31, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants