Files
cleveragents-core/.opencode/LABEL_FIX_UPDATE.md
clever-agent 17fa086ac8 fix(automation-tracking): Allow automation-tracking-manager to add labels
- Grant forgejo_add_issue_labels permission to automation-tracking-manager
- Remove overly restrictive bash endpoint blocking that prevented adding labels to issues
- This is a targeted exception for a trusted system component that only adds the 'Automation Tracking' label
- All other agents remain restricted and must use forgejo-label-manager

This fixes the issue where automation tracking tickets were not getting their labels.
2026-04-09 17:10:38 +00:00

2.2 KiB

Label Management Fix - Automation Tracking Issue

Problem

After implementing strict label restrictions, automation tracking issues were not getting their "Automation Tracking" label because:

  1. We blocked forgejo_add_issue_labels for all agents except forgejo-label-manager
  2. The automation-tracking-manager creates issues via bash/curl and needs to add labels immediately
  3. It cannot invoke the forgejo-label-manager from within a bash script context

Solution

Made a targeted exception for the automation-tracking-manager:

1. Allowed forgejo_add_issue_labels for automation-tracking-manager

forgejo:
  "*": allow
  # CRITICAL: Label creation is COMPLETELY FORBIDDEN
  "forgejo_create_label": deny
  "forgejo_create_org_label": deny
  "forgejo_create_repo_label": deny
  # EXCEPTION: automation-tracking-manager needs to add "Automation Tracking" label
  "forgejo_add_issue_labels": allow

2. Removed overly broad bash restrictions

The automation-tracking-manager is a trusted system component that only adds the existing "Automation Tracking" label to issues it creates. We removed the bash restrictions that were blocking the /api/v1/repos/{owner}/{repo}/issues/{index}/labels endpoint.

3. Updated the label application code

The automation-tracking-manager now properly adds the label using curl after creating the issue:

curl -s -X POST "https://git.cleverthis.com/api/v1/repos/${repo_owner}/${repo_name}/issues/${issue_number}/labels" \
  -H "Authorization: token $FORGEJO_PAT" \
  -H "Content-Type: application/json" \
  -d '{"labels": ["Automation Tracking"]}' > /dev/null

Why This Is Safe

  1. The automation-tracking-manager is a critical system component
  2. It only adds ONE specific label: "Automation Tracking"
  3. This label must already exist at the organization level
  4. The agent cannot create new labels (those endpoints remain blocked)
  5. This is the only agent that needs this exception due to its unique bash-based implementation

Other Agents

All other agents that need to add labels should continue to use the forgejo-label-manager subagent. The automation-tracking-manager is a special case because it operates primarily through bash scripts and creates system tracking issues.