Skip to content

Commit 11f8c88

Browse files
Beer van der DriftBeer van der Drift
authored andcommitted
ci: repo-scoped auth header for the Go SDK repo (checkout extraheader overrides URL credentials)
1 parent f151311 commit 11f8c88

1 file changed

Lines changed: 18 additions & 3 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 18 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,12 @@ jobs:
3333
GO_MODULE_REPO: context-dot-dev/context-go-sdk-staging
3434
GO_REPO_READ_TOKEN: ${{ secrets.GO_REPO_READ_TOKEN }}
3535
run: |
36-
git config --global url."https://x-access-token:${GO_REPO_READ_TOKEN}@github.com/${GO_MODULE_REPO}".insteadOf "https://github.com/${GO_MODULE_REPO}"
36+
# actions/checkout persists an Authorization header for all of github.com in the
37+
# workspace git config, which overrides URL-embedded credentials. A repo-scoped
38+
# extraheader is a longer URL match, so it takes precedence for the Go SDK repo.
39+
auth_header="AUTHORIZATION: basic $(printf 'x-access-token:%s' "$GO_REPO_READ_TOKEN" | base64 -w0)"
40+
git config --global "http.https://github.com/${GO_MODULE_REPO}.extraheader" "$auth_header"
41+
git config --global "http.https://github.com/${GO_MODULE_REPO}.git.extraheader" "$auth_header"
3742
3843
- uses: ./.github/actions/setup-go
3944
with:
@@ -67,7 +72,12 @@ jobs:
6772
GO_MODULE_REPO: context-dot-dev/context-go-sdk-staging
6873
GO_REPO_READ_TOKEN: ${{ secrets.GO_REPO_READ_TOKEN }}
6974
run: |
70-
git config --global url."https://x-access-token:${GO_REPO_READ_TOKEN}@github.com/${GO_MODULE_REPO}".insteadOf "https://github.com/${GO_MODULE_REPO}"
75+
# actions/checkout persists an Authorization header for all of github.com in the
76+
# workspace git config, which overrides URL-embedded credentials. A repo-scoped
77+
# extraheader is a longer URL match, so it takes precedence for the Go SDK repo.
78+
auth_header="AUTHORIZATION: basic $(printf 'x-access-token:%s' "$GO_REPO_READ_TOKEN" | base64 -w0)"
79+
git config --global "http.https://github.com/${GO_MODULE_REPO}.extraheader" "$auth_header"
80+
git config --global "http.https://github.com/${GO_MODULE_REPO}.git.extraheader" "$auth_header"
7181
7282
- uses: ./.github/actions/setup-go
7383
with:
@@ -122,7 +132,12 @@ jobs:
122132
GO_MODULE_REPO: context-dot-dev/context-go-sdk-staging
123133
GO_REPO_READ_TOKEN: ${{ secrets.GO_REPO_READ_TOKEN }}
124134
run: |
125-
git config --global url."https://x-access-token:${GO_REPO_READ_TOKEN}@github.com/${GO_MODULE_REPO}".insteadOf "https://github.com/${GO_MODULE_REPO}"
135+
# actions/checkout persists an Authorization header for all of github.com in the
136+
# workspace git config, which overrides URL-embedded credentials. A repo-scoped
137+
# extraheader is a longer URL match, so it takes precedence for the Go SDK repo.
138+
auth_header="AUTHORIZATION: basic $(printf 'x-access-token:%s' "$GO_REPO_READ_TOKEN" | base64 -w0)"
139+
git config --global "http.https://github.com/${GO_MODULE_REPO}.extraheader" "$auth_header"
140+
git config --global "http.https://github.com/${GO_MODULE_REPO}.git.extraheader" "$auth_header"
126141
127142
- uses: ./.github/actions/setup-go
128143
with:

0 commit comments

Comments
 (0)