Fix Claude OAuth token env for Actions - #31
Conversation
|
Warning Review limit reached
Next review available in: 49 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryThis PR updates the Claude GitHub Actions token wiring.
Confidence Score: 4/5The interactive
.github/workflows/claude.yml
|
| Filename | Overview |
|---|---|
| .github/workflows/claude.yml | Adds the Claude OAuth token to the step environment in the user-triggered @claude workflow, increasing secret exposure. |
| .github/workflows/claude-code-review.yml | Adds the same OAuth token environment variable to the automated review workflow, where the prompt and allowed tools are more constrained. |
Reviews (1): Last reviewed commit: "Fix Claude OAuth token env for Actions: ..." | Re-trigger Greptile
| env: | ||
| CLAUDE_CODE_OAUTH_TOKEN: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} |
There was a problem hiding this comment.
Comment Prompt Exposes OAuth Token
When any issue, review, or comment body containing @claude starts this workflow, that user-controlled text becomes the Claude instruction source while the action also receives CLAUDE_CODE_OAUTH_TOKEN in its process environment. Because this workflow does not restrict Claude's tools, prompt injection can read the inherited environment and leak the OAuth token; the existing with input already passed the token without adding this extra environment surface.
Context Used: CLAUDE.md (source)
Summary
CLAUDE_CODE_OAUTH_TOKENthrough the Claude action stepenvas well as the existingwith:input@claudeworkflowsWhy
anthropics/claude-code-action@v1can resolve the OAuth input empty in this runner path unless the token is also available in the inherited step env. This matches the Hichee fix proven by shakacode/hichee#9633.Verification