Current behaviour
sticky.Post (internal/sticky/sticky.go) resolves the poster's login with forge.Client.GetAuthenticatedUser and then filters marker comments by author. If that lookup fails, it logs "Could not determine bot user, marker spoofing protection degraded" and continues with an empty login. FindMarkedComment then matches on the marker alone. The result is that the first comment carrying the marker gets edited, whoever wrote it.
Why this needs a follow-up
#7243 changes fullsend issues post-comment (postTrackerStickyComment) so that it never edits a comment it cannot verify as its own:
- An existing comment matches only when both the author (exact login) and the marker match.
- If the identity cannot be resolved after a short retry, it fails with an error and posts or edits nothing. Posting a new comment instead would orphan the earlier one.
sticky.Post (used by post-comment / post-review) is now looser than that path. When identity resolution fails, it falls back to editing an unverified comment.
Ask
Bring sticky.Post to the same rule:
- When the login cannot be resolved (after a short retry), do not edit any existing comment. Return an error naming the cause instead of falling back.
- Make
FindMarkedComment with an empty login match nothing.
- Add tests for an unresolvable identity and a planted marker comment.
Out of scope for #7243.
Current behaviour
sticky.Post(internal/sticky/sticky.go) resolves the poster's login withforge.Client.GetAuthenticatedUserand then filters marker comments by author. If that lookup fails, it logs "Could not determine bot user, marker spoofing protection degraded" and continues with an empty login.FindMarkedCommentthen matches on the marker alone. The result is that the first comment carrying the marker gets edited, whoever wrote it.Why this needs a follow-up
#7243 changes
fullsend issues post-comment(postTrackerStickyComment) so that it never edits a comment it cannot verify as its own:sticky.Post(used bypost-comment/post-review) is now looser than that path. When identity resolution fails, it falls back to editing an unverified comment.Ask
Bring
sticky.Postto the same rule:FindMarkedCommentwith an empty login match nothing.Out of scope for #7243.