Skip to content

fix(pull_request_reviews): Update pending pull request review lookup to work when the authenticated actor is a Copilot bot - #3355

Open
Copilot wants to merge 3 commits into
mainfrom
copilot/fix-pending-review-lookup
Open

Copilot wants to merge 3 commits into
mainfrom
copilot/fix-pending-review-lookup

Conversation

Copilot AI commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Pull request review tools which pull the current pending review for the user don't work when authenticated with a Copilot installation (server-to-server/S2S) token.

This fixes it by changing how we pull the current pending review to to be more resilient to the specific implementation of Copilot bots.

Why

Many of our pull request review tools rely on using the GitHub GraphQL API to look up the current pending review:

  • add_comment_to_pending_review / add_pull_request_review_comment
  • submit_pending / submit_pending_pull_request_review
  • delete_pending / delete_pending_pull_request_review

Under the hood, we do this by fetching the current viewer.login and then fetching reviewers where the author matches that login.

This is currently broken for Copilot bots. When authenticated as Copilot cloud agent, the GraphQL API reports Copilot for viewer.login, but this isn't the bot's real login.

The real login is copilot-swe-agent (the bot identity represented as copilot-swe-agent[bot] elsewhere).

Filtering the reviews connection with the reported viewer login therefore returns no pending review, so adding comments, submitting, and deleting pending reviews fail.

GraphQL node IDs are stable across those representations, so they are a more reliable identity key.

No linked issue.

What changed

  • Query viewer.id instead of viewer.login.
  • Load PENDING reviews without an author-login filter, paginate them, and select the first review whose author node ID matches the viewer node ID.
  • Select IDs through concrete Actor fragments because the interface does not expose id; compare only globally unique node IDs because this token presents the viewer as User and the review author as Bot.
  • Share the lookup across comment, submit, and delete operations, with coverage that skips another user's pending review before selecting the viewer's review.

MCP impact

  • No tool or API changes
  • Tool schema or behavior changed
  • New tool added

The schemas are unchanged. The existing pending-review operations now work when the authenticated viewer's reported login does not match the review author's real login.

Prompts tested (tool changes only)

  • "Add this comment to my pending review."
  • "Submit my pending review as a comment."
  • "Delete my pending review."

Live validation on this draft used the built MCP server over stdio to create a pending review, add a line comment, and submit it. The old author: "Copilot" query returned no review, while the new query matched viewer and author node ID BOT_kgDOC9w8XQ.

Security / limits

  • No security or limits impact
  • Auth / permissions considered
  • Data exposure, filtering, or token/size limits considered

The API currently returns only the viewer's own pending reviews, but the client still matches author ID defensively in case that behavior changes. Results are fetched in pages of 100 and stop as soon as the viewer's review is found.

Tool renaming

  • I am renaming tools as part of this PR (e.g. a part of a consolidation effort)
    • I have added the new tool aliases in deprecated_tool_aliases.go
  • I am not renaming tools as part of this PR

Lint & tests

  • Linted locally with ./script/lint
  • Tested locally with ./script/test

gofmt -s, go vet ./..., focused tests, the full race-enabled test suite, and the live MCP create/comment/submit flow pass. ./script/lint could not install golangci-lint because its installer host is blocked in this environment; running the pinned linter through Go modules reached a Go export-data compatibility error.

Docs

  • Not needed
  • Updated (README / docs / examples)

Use stable GraphQL node IDs instead of viewer login values when selecting the current user's pending pull request review.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Validated the pending-review create, comment, and submit flow through the local MCP server using the Copilot SWE agent token.

return utils.NewToolResultText("pull request review comment successfully added to pending review"), nil
}

func getPendingPullRequestReviewForViewer(ctx context.Context, client *githubv4.Client, owner, repo string, pullNumber int32) (*githubv4.ID, *mcp.CallToolResult) {

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Live MCP validation: concrete Actor fragments expose the stable node ID even when viewer and review author types differ.

Select actor node IDs through GraphQL fragments because the Actor interface does not expose id directly.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@timrogers
timrogers marked this pull request as ready for review September 30, 2026 15:00
@timrogers
timrogers requested a review from a team as a code owner September 30, 2026 15:00
Copilot AI balanced review requested due to automatic review settings September 30, 2026 15:00
@timrogers timrogers changed the title Fix pending review lookup for masked logins fix(pull_request_reviews): Update pending pull request review lookup to work when the authenticated actor is a Copilot bot Sep 30, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The newly introduced pagination and cursor-update path lacks coverage.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Updates pending-review lookup to match authenticated actors by stable node ID, fixing Copilot bot operations.

Changes:

  • Centralizes pending-review lookup across comment, submit, and delete operations.
  • Filters and paginates pending reviews, matching viewer and author node IDs.
  • Updates mocks and tests for User/Bot identity matching.
File Description
pkg/​github/​pullrequests.go Implements shared node-ID-based review lookup.
pkg/​github/​pullrequests_test.go Updates pending-review tests and GraphQL mocks.
pkg/​github/​granular_tools_test.go Adapts granular tool testing to ID-based lookup.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pkg/github/pullrequests.go
Cover cursor propagation and viewer review selection on a second page.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants