From 1b3f3ec24c1652f3abc1dd339f185a57aa57a51f Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Fri, 10 Apr 2026 22:19:28 +0000 Subject: [PATCH 1/2] Block disable-all-workflows.sh if logged-in user does not match repo owner Agent-Logs-Url: https://github.com/mikeharder/scripts/sessions/96b02a24-128e-4e30-930c-8f638241475c Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com> --- disable-all-workflows.sh | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/disable-all-workflows.sh b/disable-all-workflows.sh index 152697b..47078f1 100755 --- a/disable-all-workflows.sh +++ b/disable-all-workflows.sh @@ -22,6 +22,13 @@ if ! gh auth status > /dev/null 2>&1; then exit 1 fi +# block if the logged-in user does not match the target repo owner +LOGGED_IN_USER=$(gh api /user --jq '.login') +if [[ "${LOGGED_IN_USER}" != "${OWNER}" ]]; then + echo "❌ Logged-in user '${LOGGED_IN_USER}' does not match repo owner '${OWNER}'. Aborting." + exit 1 +fi + # get IDs of only active workflows active_ids=$(gh api \ --method GET \ From de88e27c9416f2bdd9963ca37b8a0147b727bee3 Mon Sep 17 00:00:00 2001 From: Mike Harder Date: Fri, 10 Apr 2026 22:31:05 +0000 Subject: [PATCH 2/2] get logged in user from `gh auth` --- disable-all-workflows.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/disable-all-workflows.sh b/disable-all-workflows.sh index 47078f1..e80498d 100755 --- a/disable-all-workflows.sh +++ b/disable-all-workflows.sh @@ -23,7 +23,7 @@ if ! gh auth status > /dev/null 2>&1; then fi # block if the logged-in user does not match the target repo owner -LOGGED_IN_USER=$(gh api /user --jq '.login') +LOGGED_IN_USER=$(gh auth status --json hosts --jq '.hosts["github.com"][] | select(.active) | .login') if [[ "${LOGGED_IN_USER}" != "${OWNER}" ]]; then echo "❌ Logged-in user '${LOGGED_IN_USER}' does not match repo owner '${OWNER}'. Aborting." exit 1