The dedupe bot comment built by scripts/comment-on-duplicates.sh promises (line 89):
To prevent auto-closure, add a comment or 馃憥 this comment
with no author qualifier. But scripts/auto-close-duplicates.ts (line 228-231) only counts a -1 reaction when reaction.user.id === issue.user.id, so a thumbs-down from anyone other than the issue author is silently ignored and the issue still auto-closes.
The parallel comment path has no such filter: a comment from any user blocks closure (commentsAfterDupe checks no author). Honoring any user's thumbs-down makes the two paths consistent and grants no new abuse surface, since anyone can already block closure by commenting.
An alternative would be rewording the bot comment to say "the issue author can 馃憥", but matching the code to the promise (and to the comment path) seems strictly better for reporters whose duplicates were misdetected. Happy to open a PR.
The dedupe bot comment built by
scripts/comment-on-duplicates.shpromises (line 89):with no author qualifier. But
scripts/auto-close-duplicates.ts(line 228-231) only counts a-1reaction whenreaction.user.id === issue.user.id, so a thumbs-down from anyone other than the issue author is silently ignored and the issue still auto-closes.The parallel comment path has no such filter: a comment from any user blocks closure (
commentsAfterDupechecks no author). Honoring any user's thumbs-down makes the two paths consistent and grants no new abuse surface, since anyone can already block closure by commenting.An alternative would be rewording the bot comment to say "the issue author can 馃憥", but matching the code to the promise (and to the comment path) seems strictly better for reporters whose duplicates were misdetected. Happy to open a PR.