🔒 security(ci): keep sync token out of remote url via GIT_ASKPASS
- inline .gitea/ci/sync_tsl_playbook.sh into sync-tsl-playbook.yml - clone over plain repo url; credentials flow through an ephemeral GIT_ASKPASS helper removed in cleanup - rewrite tests to extract and exercise the workflow run block Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -9,7 +9,7 @@ from pathlib import Path
|
||||
|
||||
ROOT = Path(__file__).resolve().parents[1]
|
||||
SCRIPT = ROOT / "scripts" / "build_tsl_playbook.py"
|
||||
SYNC_SCRIPT = ROOT / ".gitea" / "ci" / "sync_tsl_playbook.sh"
|
||||
SYNC_WORKFLOW = ROOT / ".gitea" / "workflows" / "sync-tsl-playbook.yml"
|
||||
|
||||
|
||||
class BuildTslPlaybookTests(unittest.TestCase):
|
||||
@@ -61,16 +61,23 @@ class BuildTslPlaybookTests(unittest.TestCase):
|
||||
output_skill = count_files(output / "skills" / "tsl-api-reference")
|
||||
self.assertEqual(output_skill, source_skill)
|
||||
|
||||
def test_sync_script_does_not_remove_entire_target_branch(self):
|
||||
text = SYNC_SCRIPT.read_text(encoding="utf-8")
|
||||
def test_sync_workflow_does_not_remove_entire_target_branch(self):
|
||||
text = SYNC_WORKFLOW.read_text(encoding="utf-8")
|
||||
|
||||
self.assertNotRegex(text, r"git rm -rf --quiet\s+\.")
|
||||
self.assertIn("generated_paths=(AGENTS.md docs skills)", text)
|
||||
self.assertIn('git add -A "${generated_paths[@]}"', text)
|
||||
self.assertNotIn(".gitea/ci/", text)
|
||||
self.assertNotIn("https://oauth2", text)
|
||||
self.assertNotIn("oauth2:${TOKEN}", text)
|
||||
self.assertNotRegex(text, r"REPO_URL=.*(TOKEN|WORKFLOW)")
|
||||
self.assertNotIn("git remote set-url", text)
|
||||
self.assertIn("GIT_ASKPASS", text)
|
||||
self.assertIn('REPO_URL="${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}.git"', text)
|
||||
|
||||
def test_sync_preserves_files_outside_generated_paths(self):
|
||||
if shutil.which("bash") is None:
|
||||
self.skipTest("bash is required to run sync_tsl_playbook.sh")
|
||||
self.skipTest("bash is required to run sync workflow script")
|
||||
|
||||
with tempfile.TemporaryDirectory() as tmp_dir:
|
||||
repo = create_source_repo(Path(tmp_dir))
|
||||
@@ -104,7 +111,7 @@ class BuildTslPlaybookTests(unittest.TestCase):
|
||||
|
||||
def test_sync_creates_new_branch_without_source_files(self):
|
||||
if shutil.which("bash") is None:
|
||||
self.skipTest("bash is required to run sync_tsl_playbook.sh")
|
||||
self.skipTest("bash is required to run sync workflow script")
|
||||
|
||||
with tempfile.TemporaryDirectory() as tmp_dir:
|
||||
repo = create_source_repo(Path(tmp_dir))
|
||||
@@ -119,7 +126,7 @@ class BuildTslPlaybookTests(unittest.TestCase):
|
||||
git(repo, "cat-file", "-e", f"HEAD:{path}")
|
||||
|
||||
for path in (
|
||||
".gitea/ci/sync_tsl_playbook.sh",
|
||||
".gitea/workflows/sync-tsl-playbook.yml",
|
||||
"scripts/build_tsl_playbook.py",
|
||||
"rulesets/tsl/index.md",
|
||||
):
|
||||
@@ -159,22 +166,32 @@ def run_sync(repo: Path) -> None:
|
||||
"COMMIT_AUTHOR_EMAIL": "test@example.invalid",
|
||||
}
|
||||
)
|
||||
result = subprocess.run(
|
||||
["bash", ".gitea/ci/sync_tsl_playbook.sh"],
|
||||
cwd=repo,
|
||||
env=env,
|
||||
capture_output=True,
|
||||
text=True,
|
||||
encoding="utf-8",
|
||||
errors="replace",
|
||||
)
|
||||
with tempfile.NamedTemporaryFile(
|
||||
"w", suffix=".sh", encoding="utf-8", newline="\n", delete=False
|
||||
) as script_file:
|
||||
script_file.write(extract_sync_workflow_script())
|
||||
script_path = script_file.name
|
||||
try:
|
||||
result = subprocess.run(
|
||||
["bash", script_path],
|
||||
cwd=repo,
|
||||
env=env,
|
||||
capture_output=True,
|
||||
text=True,
|
||||
encoding="utf-8",
|
||||
errors="replace",
|
||||
)
|
||||
finally:
|
||||
os.unlink(script_path)
|
||||
if result.returncode != 0:
|
||||
raise AssertionError(result.stderr + result.stdout)
|
||||
|
||||
|
||||
def copy_required_sources(repo: Path) -> None:
|
||||
(repo / ".gitea" / "ci").mkdir(parents=True)
|
||||
shutil.copy2(SYNC_SCRIPT, repo / ".gitea" / "ci" / "sync_tsl_playbook.sh")
|
||||
(repo / ".gitea" / "workflows").mkdir(parents=True)
|
||||
shutil.copy2(
|
||||
SYNC_WORKFLOW, repo / ".gitea" / "workflows" / "sync-tsl-playbook.yml"
|
||||
)
|
||||
|
||||
(repo / "scripts").mkdir()
|
||||
shutil.copy2(SCRIPT, repo / "scripts" / "build_tsl_playbook.py")
|
||||
@@ -203,6 +220,36 @@ def count_files(path: Path) -> int:
|
||||
return sum(1 for item in path.rglob("*") if item.is_file())
|
||||
|
||||
|
||||
def extract_sync_workflow_script() -> str:
|
||||
lines = SYNC_WORKFLOW.read_text(encoding="utf-8").splitlines()
|
||||
in_sync_step = False
|
||||
in_run_block = False
|
||||
script_lines: list[str] = []
|
||||
|
||||
for line in lines:
|
||||
if line.startswith(" - name: 📦 Build and publish tsl-playbook"):
|
||||
in_sync_step = True
|
||||
continue
|
||||
if in_sync_step and line.startswith(" - name: "):
|
||||
break
|
||||
if in_sync_step and line == " run: |":
|
||||
in_run_block = True
|
||||
continue
|
||||
if not in_run_block:
|
||||
continue
|
||||
if line.startswith(" "):
|
||||
script_lines.append(line[10:])
|
||||
continue
|
||||
if line.strip() == "":
|
||||
script_lines.append("")
|
||||
continue
|
||||
break
|
||||
|
||||
if not script_lines:
|
||||
raise AssertionError("sync workflow run block was not found")
|
||||
return "\n".join(script_lines) + "\n"
|
||||
|
||||
|
||||
def git(repo: Path, *args: str) -> subprocess.CompletedProcess[str]:
|
||||
return run(["git", *args], cwd=repo)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user