From 919492df1347127f14f92e4732d9b0d862a1a0ba Mon Sep 17 00:00:00 2001 From: neil Date: Mon, 6 Jul 2026 16:27:26 +0800 Subject: [PATCH] wiki-guard: use WIKI_GUARD_TOKEN (PAT with read:org) to enumerate org write members --- .github/workflows/wiki-guard.yml | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/.github/workflows/wiki-guard.yml b/.github/workflows/wiki-guard.yml index 45033554..6c392d37 100644 --- a/.github/workflows/wiki-guard.yml +++ b/.github/workflows/wiki-guard.yml @@ -43,7 +43,10 @@ jobs: - name: Enforce wiki rules id: guard env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + # WIKI_GUARD_TOKEN: a PAT with read:org, needed to enumerate + # members whose write access comes via the organization -- the + # repo-scoped GITHUB_TOKEN only sees direct collaborators. + GH_TOKEN: ${{ secrets.WIKI_GUARD_TOKEN || secrets.GITHUB_TOKEN }} run: | # Logins with write (push) access to the repository, including # organization members -- they may delete/rename pages and edit @@ -54,6 +57,7 @@ jobs: -q '.[] | select(.permissions.push) | .login' 2>/dev/null \ | tr 'A-Z' 'a-z' | sort -u > writers.txt || true echo "write-access members loaded: $(wc -l < writers.txt)" + cat writers.txt cd wiki git config core.quotePath false