ci(facts): use the existing org-level REGISTRY_TOKEN
All checks were successful
PR checks / checks (pull_request) Successful in 9m11s
All checks were successful
PR checks / checks (pull_request) Successful in 9m11s
checkFacts needs to read link, servuo-plugins, website and installer, and the automatic per-run token is scoped to this repo alone. Rather than mint a new secret, the workflow uses REGISTRY_TOKEN, which already exists at the org level with the right permissions. The secret is named for the registry and the script reads GITEA_TOKEN; the mapping stays in the workflow so the script keeps asking for what it actually wants -- a Gitea token -- rather than this org's secret name. Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -44,11 +44,15 @@ jobs:
|
|||||||
#
|
#
|
||||||
# This needs a token that can read the OTHER repositories in the org: link,
|
# This needs a token that can read the OTHER repositories in the org: link,
|
||||||
# servuo-plugins, website and installer. The automatic per-run token is scoped
|
# servuo-plugins, website and installer. The automatic per-run token is scoped
|
||||||
# to this repository alone and will 404 on all four, so the job reads an
|
# to this repository alone and 404s on all four, so the job uses the org-level
|
||||||
# org-level secret instead.
|
# REGISTRY_TOKEN, which already exists and already carries the right scope.
|
||||||
|
#
|
||||||
|
# The secret is named for the registry; the script reads GITEA_TOKEN. Mapping it
|
||||||
|
# here rather than renaming either side keeps the script's interface honest — it
|
||||||
|
# wants a Gitea token, not this org's particular secret.
|
||||||
#
|
#
|
||||||
# It runs last, and it is the only step that touches the network, so a Gitea
|
# It runs last, and it is the only step that touches the network, so a Gitea
|
||||||
# outage cannot mask a real failure in the build.
|
# outage cannot mask a real failure in the build.
|
||||||
env:
|
env:
|
||||||
GITEA_TOKEN: ${{ secrets.PLATFORM_READ_TOKEN }}
|
GITEA_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
||||||
run: npm run check:facts
|
run: npm run check:facts
|
||||||
|
|||||||
@@ -56,7 +56,9 @@ on protocol 3, because every checkout in the workspace sat on a feature branch w
|
|||||||
never been fetched.
|
never been fetched.
|
||||||
|
|
||||||
It needs a token — anonymous raw fetches fail on this Gitea instance, and a check that silently skips
|
It needs a token — anonymous raw fetches fail on this Gitea instance, and a check that silently skips
|
||||||
itself is worse than no check at all.
|
itself is worse than no check at all. It must be able to read the other repositories in the
|
||||||
|
organisation, not just this one. CI already has this: the workflow maps the org-level
|
||||||
|
`REGISTRY_TOKEN` secret into `GITEA_TOKEN` for that step.
|
||||||
|
|
||||||
**`checkTokens.mjs`** fails the build if a colour literal appears anywhere in `src/` outside
|
**`checkTokens.mjs`** fails the build if a colour literal appears anywhere in `src/` outside
|
||||||
`src/styles/tokens.css`. §7 promises that recolouring the site is a file copy and a container
|
`src/styles/tokens.css`. §7 promises that recolouring the site is a file copy and a container
|
||||||
|
|||||||
@@ -231,8 +231,9 @@ async function main() {
|
|||||||
'checkFacts: GITEA_TOKEN is not set.\n\n' +
|
'checkFacts: GITEA_TOKEN is not set.\n\n' +
|
||||||
' Anonymous raw fetches fail on this Gitea instance, and a fact check that skips\n' +
|
' Anonymous raw fetches fail on this Gitea instance, and a fact check that skips\n' +
|
||||||
' itself is worse than no fact check — a stale version would ship silently.\n\n' +
|
' itself is worse than no fact check — a stale version would ship silently.\n\n' +
|
||||||
' Locally: GITEA_TOKEN=$(grep -o "[^=]*$" ~/.gitea_token_claude) npm run check:facts\n' +
|
' Locally: GITEA_TOKEN=<a token that can read the org> npm run check:facts\n' +
|
||||||
' In CI: set GITEA_TOKEN from the repository secret.\n'
|
' In CI: already wired — .gitea/workflows/pr-checks.yml maps the org-level\n' +
|
||||||
|
' REGISTRY_TOKEN secret into GITEA_TOKEN for this step.\n'
|
||||||
);
|
);
|
||||||
process.exit(2);
|
process.exit(2);
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user