Authenticate the npm publish with Basic, and sharpen the triage
build / build (push) Has been cancelled
build / build (push) Has been cancelled
This commit is contained in:
@@ -108,6 +108,18 @@ jobs:
|
||||
curl -s -o /dev/null -w '%{http_code}\n' \
|
||||
-u "${GITEA_OWNER}:$TOKEN" \
|
||||
"https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/npm/@maxvojtkov%2Fpulumi-dokploy"
|
||||
# A write with a deliberately empty body: 401 means the credentials
|
||||
# were refused, anything else means they were accepted and only the
|
||||
# payload was rejected. That is what separates "wrong token" from
|
||||
# "wrong auth scheme".
|
||||
echo -n "npm PUT (bearer, as npm) -> "
|
||||
curl -s -o /dev/null -w '%{http_code}\n' -X PUT \
|
||||
-H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \
|
||||
-d '{}' "https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/npm/@maxvojtkov%2Fpulumi-dokploy"
|
||||
echo -n "npm PUT (basic) -> "
|
||||
curl -s -o /dev/null -w '%{http_code}\n' -X PUT \
|
||||
-u "${GITEA_OWNER}:$TOKEN" -H 'Content-Type: application/json' \
|
||||
-d '{}' "https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/npm/@maxvojtkov%2Fpulumi-dokploy"
|
||||
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
@@ -159,9 +171,13 @@ jobs:
|
||||
env:
|
||||
TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||
run: |
|
||||
# `_authToken` makes npm send `Authorization: Bearer`, which this
|
||||
# Gitea refuses for the token Actions injects -- the publish failed
|
||||
# with E401 while the very same token authenticated fine over Basic.
|
||||
# `_auth` is base64 user:token, i.e. Basic.
|
||||
cat > .npmrc <<EOF
|
||||
@maxvojtkov:registry=https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/npm/
|
||||
//${GITEA_HOST}/api/packages/${GITEA_OWNER}/npm/:_authToken=${TOKEN}
|
||||
//${GITEA_HOST}/api/packages/${GITEA_OWNER}/npm/:_auth=$(printf '%s:%s' "${GITEA_OWNER}" "${TOKEN}" | base64 -w0)
|
||||
EOF
|
||||
npm publish
|
||||
|
||||
|
||||
Reference in New Issue
Block a user