|
33 | 33 | GO_MODULE_REPO: context-dot-dev/context-go-sdk-staging |
34 | 34 | GO_REPO_READ_TOKEN: ${{ secrets.GO_REPO_READ_TOKEN }} |
35 | 35 | run: | |
36 | | - git config --global url."https://x-access-token:${GO_REPO_READ_TOKEN}@github.com/${GO_MODULE_REPO}".insteadOf "https://github.com/${GO_MODULE_REPO}" |
| 36 | + # actions/checkout persists an Authorization header for all of github.com in the |
| 37 | + # workspace git config, which overrides URL-embedded credentials. A repo-scoped |
| 38 | + # extraheader is a longer URL match, so it takes precedence for the Go SDK repo. |
| 39 | + auth_header="AUTHORIZATION: basic $(printf 'x-access-token:%s' "$GO_REPO_READ_TOKEN" | base64 -w0)" |
| 40 | + git config --global "http.https://github.com/${GO_MODULE_REPO}.extraheader" "$auth_header" |
| 41 | + git config --global "http.https://github.com/${GO_MODULE_REPO}.git.extraheader" "$auth_header" |
37 | 42 |
|
38 | 43 | - uses: ./.github/actions/setup-go |
39 | 44 | with: |
|
67 | 72 | GO_MODULE_REPO: context-dot-dev/context-go-sdk-staging |
68 | 73 | GO_REPO_READ_TOKEN: ${{ secrets.GO_REPO_READ_TOKEN }} |
69 | 74 | run: | |
70 | | - git config --global url."https://x-access-token:${GO_REPO_READ_TOKEN}@github.com/${GO_MODULE_REPO}".insteadOf "https://github.com/${GO_MODULE_REPO}" |
| 75 | + # actions/checkout persists an Authorization header for all of github.com in the |
| 76 | + # workspace git config, which overrides URL-embedded credentials. A repo-scoped |
| 77 | + # extraheader is a longer URL match, so it takes precedence for the Go SDK repo. |
| 78 | + auth_header="AUTHORIZATION: basic $(printf 'x-access-token:%s' "$GO_REPO_READ_TOKEN" | base64 -w0)" |
| 79 | + git config --global "http.https://github.com/${GO_MODULE_REPO}.extraheader" "$auth_header" |
| 80 | + git config --global "http.https://github.com/${GO_MODULE_REPO}.git.extraheader" "$auth_header" |
71 | 81 |
|
72 | 82 | - uses: ./.github/actions/setup-go |
73 | 83 | with: |
@@ -122,7 +132,12 @@ jobs: |
122 | 132 | GO_MODULE_REPO: context-dot-dev/context-go-sdk-staging |
123 | 133 | GO_REPO_READ_TOKEN: ${{ secrets.GO_REPO_READ_TOKEN }} |
124 | 134 | run: | |
125 | | - git config --global url."https://x-access-token:${GO_REPO_READ_TOKEN}@github.com/${GO_MODULE_REPO}".insteadOf "https://github.com/${GO_MODULE_REPO}" |
| 135 | + # actions/checkout persists an Authorization header for all of github.com in the |
| 136 | + # workspace git config, which overrides URL-embedded credentials. A repo-scoped |
| 137 | + # extraheader is a longer URL match, so it takes precedence for the Go SDK repo. |
| 138 | + auth_header="AUTHORIZATION: basic $(printf 'x-access-token:%s' "$GO_REPO_READ_TOKEN" | base64 -w0)" |
| 139 | + git config --global "http.https://github.com/${GO_MODULE_REPO}.extraheader" "$auth_header" |
| 140 | + git config --global "http.https://github.com/${GO_MODULE_REPO}.git.extraheader" "$auth_header" |
126 | 141 |
|
127 | 142 | - uses: ./.github/actions/setup-go |
128 | 143 | with: |
|
0 commit comments