Skip to content

fix: Fix PR review tools (except create_pull_request_review which works already) when authenticated with a GitHub App installation token (S2S) - #3353

Closed
Copilot wants to merge 1 commit into
mainfrom
copilot/bot-pending-pr-reviews
Closed

Copilot wants to merge 1 commit into
mainfrom
copilot/bot-pending-pr-reviews

Conversation

Copilot AI commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Creating a pending PR review (create_pull_request_review tool or pull_request_review_write tool with method: create) works when authenticated with a GitHub App installation token.

However, the other PR review related tools don't work, becuase they try to use the GraphQL API to find the current pendig review, and this API doesn't behave correctly for bot actors.

This fixes it by identifying the pending review using the REST API rather than the GraphQL API. Everything else stays the same.

Why

When authenticated with a GitHub App installation/server-to-server token, GitHub uses the app's bot user as the "viewer" and review author.

The initial create operation works because it creates a review directly on the pull request and does not need to rediscover it.

The subsequent operations receive only the repository and pull request number, so they must first look up the current caller's pending review:

  • add_comment_to_pending_review / add_pull_request_review_comment
  • submit_pending / submit_pending_pull_request_review
  • delete_pending / delete_pending_pull_request_review

That lookup currently fails with an installation token. Live testing showed that the review is successfully created and is visible through REST as PENDING, but the GraphQL API's viewerLatestReview returns null. The follow-up tools therefore report that no pending review exists and cannot comment on, submit, or delete it.

We can revisit whether the upstream behavior/API should change for bot viewers, but the MCP server needs to behave correctly with the public APIs available today.

What changed

  • For operations that need an existing pending review, list pull request reviews through REST with per_page=100, following pagination until the caller-visible PENDING review is found.
  • Use the REST review's GraphQL node_id with the existing GraphQL comment, submit, and delete mutations.
  • Apply the hybrid lookup to both consolidated and granular pull request review tools.
  • Cover pagination, missing reviews, submitted-only reviews, missing node IDs, REST failures, and the existing GraphQL mutations.

MCP impact

  • No tool or API changes
  • Tool schema or behavior changed
  • New tool added

Tool schemas and response text are unchanged. Existing pending-review operations now work when authenticated with GitHub App installation/server-to-server tokens and acting as the app's bot user.

Prompts tested (tool changes only)

  • "Create a pending review on this pull request."
  • "Add an inline comment to the pending review on package-lock.json."
  • "Submit the pending review as a comment."

Security / limits

  • No security or limits impact
  • Auth / permissions considered
  • Data exposure, filtering, or token/size limits considered

The live workflow used a GitHub App installation/server-to-server token with pull request write access, causing requests to act as timrogers-github-app-testing[bot]. REST only exposes pending reviews to their author, so selecting the visible PENDING review does not require login normalization. Review listing is paginated at 100 reviews per request and continues until the pending review is found.

Tool renaming

  • I am renaming tools as part of this PR (e.g. a part of a consolidation effort)
    • I have added the new tool aliases in deprecated_tool_aliases.go
  • I am not renaming tools as part of this PR

Note: if you're renaming tools, you must add the tool aliases. For more information on how to do so, please refer to the official docs.

Lint & tests

  • Linted locally with ./script/lint — passed with 0 issues.
  • Tested locally with ./script/test — passed, including the full race-enabled suite.

Additional validation:

  • Targeted hybrid lookup and mutation tests passed, including a pending review located on page 2.
  • go build -o /tmp/github-mcp-server-branch ./cmd/github-mcp-server passed.
  • A GitHub App installation token completed two live workflows on timrogers/iata-code-decoder-api#1446:

Docs

  • Not needed
  • Updated (README / docs / examples)

No tool schema, tool name, configuration, or user-facing workflow changed.

This comment has been minimized.

@timrogers
timrogers force-pushed the copilot/bot-pending-pr-reviews branch from 484f1a1 to 6a6bc47 Compare September 30, 2026 05:06
@timrogers timrogers changed the title fix: look up pending PR reviews without viewer login fix: support pending PR reviews for GitHub Apps Sep 30, 2026
@timrogers timrogers changed the title fix: support pending PR reviews for GitHub Apps fix: support PR review tools when authenticated with a GitHub App installation token Sep 30, 2026
@timrogers
timrogers marked this pull request as ready for review September 30, 2026 05:13
@timrogers
timrogers requested a review from a team as a code owner September 30, 2026 05:13
Copilot AI balanced review requested due to automatic review settings September 30, 2026 05:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The REST error path can leak response bodies and eventually exhaust connections.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Enables pending pull-request review operations for GitHub App installation tokens by using REST review lookup with existing GraphQL mutations.

Changes:

  • Finds pending reviews through paginated REST requests.
  • Applies the lookup to consolidated and granular tools.
  • Adds pagination and failure-path tests.
File Description
pkg/​github/​pullrequests.go Adds REST pending-review lookup.
pkg/​github/​pullrequests_test.go Tests lookup, pagination, and errors.
pkg/​github/​pullrequests_granular.go Integrates REST lookup into granular tools.
pkg/​github/​granular_tools_test.go Updates granular comment test setup.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pkg/github/pullrequests.go
@timrogers timrogers changed the title fix: support PR review tools when authenticated with a GitHub App installation token fix: Fix PR review tools (except create_pull_request_review which works already) when authenticated with a GitHub App installation token (S2S) Sep 30, 2026
Use the REST reviews endpoint to locate the caller-visible pending review and retain GraphQL for comment, submit, and delete mutations. This supports GitHub App installation tokens, for which viewerLatestReview excludes pending reviews.

Add pagination coverage and update both consolidated and granular review tools without changing their schemas.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: f5bfbcc5-06e4-4487-910f-6a2ca7b5bd7b
@timrogers
timrogers force-pushed the copilot/bot-pending-pr-reviews branch from 6a6bc47 to a7d2b3b Compare September 30, 2026 05:20
@timrogers

Copy link
Copy Markdown
Contributor

I looked into the possibility of fixing this in the GitHub API, but it looks like the complexity would be high.

In the API, viewer currently never supports GitHub App installation actors, so we'd have to make a big change there or introduce a special field to solve this case.

The implementation here, leaning on REST, feels like the practical solution.

@timrogers

Copy link
Copy Markdown
Contributor

After more digging into the monolith code and what's going on here, I don't think this is the right approach. I'll think on it some more.

@timrogers timrogers closed this Sep 30, 2026
@Aziz1144

Copy link
Copy Markdown

Пиши мне в телефон телеграмм вапсап

@rananisarsb51214

Copy link
Copy Markdown

copilot/bot-pending-pr-reviews

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants