mirror of
				https://github.com/actions/checkout.git
				synced 2025-10-31 07:30:32 +00:00 
			
		
		
		
	Compare commits
	
		
			1 Commits
		
	
	
		
			v2.1.0
			...
			users/eric
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
|   | 8c9b201842 | 
							
								
								
									
										49
									
								
								.github/workflows/test.yml
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										49
									
								
								.github/workflows/test.yml
									
									
									
									
										vendored
									
									
								
							| @@ -19,6 +19,8 @@ jobs: | |||||||
|       - run: npm run build |       - run: npm run build | ||||||
|       - run: npm run format-check |       - run: npm run format-check | ||||||
|       - run: npm run lint |       - run: npm run lint | ||||||
|  |       - run: npm run pack | ||||||
|  |       - run: npm run gendocs | ||||||
|       - run: npm test |       - run: npm test | ||||||
|       - name: Verify no unstaged changes |       - name: Verify no unstaged changes | ||||||
|         run: __test__/verify-no-unstaged-changes.sh |         run: __test__/verify-no-unstaged-changes.sh | ||||||
| @@ -35,7 +37,7 @@ jobs: | |||||||
|         uses: actions/checkout@v2 |         uses: actions/checkout@v2 | ||||||
|  |  | ||||||
|       # Basic checkout |       # Basic checkout | ||||||
|       - name: Checkout basic |       - name: Basic checkout | ||||||
|         uses: ./ |         uses: ./ | ||||||
|         with: |         with: | ||||||
|           ref: test-data/v2/basic |           ref: test-data/v2/basic | ||||||
| @@ -48,7 +50,7 @@ jobs: | |||||||
|       - name: Modify work tree |       - name: Modify work tree | ||||||
|         shell: bash |         shell: bash | ||||||
|         run: __test__/modify-work-tree.sh |         run: __test__/modify-work-tree.sh | ||||||
|       - name: Checkout clean |       - name: Clean checkout | ||||||
|         uses: ./ |         uses: ./ | ||||||
|         with: |         with: | ||||||
|           ref: test-data/v2/basic |           ref: test-data/v2/basic | ||||||
| @@ -58,12 +60,12 @@ jobs: | |||||||
|         run: __test__/verify-clean.sh |         run: __test__/verify-clean.sh | ||||||
|  |  | ||||||
|       # Side by side |       # Side by side | ||||||
|       - name: Checkout side by side 1 |       - name: Side by side checkout 1 | ||||||
|         uses: ./ |         uses: ./ | ||||||
|         with: |         with: | ||||||
|           ref: test-data/v2/side-by-side-1 |           ref: test-data/v2/side-by-side-1 | ||||||
|           path: side-by-side-1 |           path: side-by-side-1 | ||||||
|       - name: Checkout side by side 2 |       - name: Side by side checkout 2 | ||||||
|         uses: ./ |         uses: ./ | ||||||
|         with: |         with: | ||||||
|           ref: test-data/v2/side-by-side-2 |           ref: test-data/v2/side-by-side-2 | ||||||
| @@ -73,7 +75,7 @@ jobs: | |||||||
|         run: __test__/verify-side-by-side.sh |         run: __test__/verify-side-by-side.sh | ||||||
|  |  | ||||||
|       # LFS |       # LFS | ||||||
|       - name: Checkout LFS |       - name: LFS checkout | ||||||
|         uses: ./ |         uses: ./ | ||||||
|         with: |         with: | ||||||
|           repository: actions/checkout # hardcoded, otherwise doesn't work from a fork |           repository: actions/checkout # hardcoded, otherwise doesn't work from a fork | ||||||
| @@ -84,35 +86,6 @@ jobs: | |||||||
|         shell: bash |         shell: bash | ||||||
|         run: __test__/verify-lfs.sh |         run: __test__/verify-lfs.sh | ||||||
|  |  | ||||||
|       # Submodules false |  | ||||||
|       - name: Checkout submodules false |  | ||||||
|         uses: ./ |  | ||||||
|         with: |  | ||||||
|           ref: test-data/v2/submodule-ssh-url |  | ||||||
|           path: submodules-false |  | ||||||
|       - name: Verify submodules false |  | ||||||
|         run: __test__/verify-submodules-false.sh |  | ||||||
|  |  | ||||||
|       # Submodules one level |  | ||||||
|       - name: Checkout submodules true |  | ||||||
|         uses: ./ |  | ||||||
|         with: |  | ||||||
|           ref: test-data/v2/submodule-ssh-url |  | ||||||
|           path: submodules-true |  | ||||||
|           submodules: true |  | ||||||
|       - name: Verify submodules true |  | ||||||
|         run: __test__/verify-submodules-true.sh |  | ||||||
|  |  | ||||||
|       # Submodules recursive |  | ||||||
|       - name: Checkout submodules recursive |  | ||||||
|         uses: ./ |  | ||||||
|         with: |  | ||||||
|           ref: test-data/v2/submodule-ssh-url |  | ||||||
|           path: submodules-recursive |  | ||||||
|           submodules: recursive |  | ||||||
|       - name: Verify submodules recursive |  | ||||||
|         run: __test__/verify-submodules-recursive.sh |  | ||||||
|  |  | ||||||
|       # Basic checkout using REST API |       # Basic checkout using REST API | ||||||
|       - name: Remove basic |       - name: Remove basic | ||||||
|         if: runner.os != 'windows' |         if: runner.os != 'windows' | ||||||
| @@ -127,7 +100,7 @@ jobs: | |||||||
|       - name: Override git version (Windows) |       - name: Override git version (Windows) | ||||||
|         if: runner.os == 'windows' |         if: runner.os == 'windows' | ||||||
|         run: __test__\\override-git-version.cmd |         run: __test__\\override-git-version.cmd | ||||||
|       - name: Checkout basic using REST API |       - name: Basic checkout using REST API | ||||||
|         uses: ./ |         uses: ./ | ||||||
|         with: |         with: | ||||||
|           ref: test-data/v2/basic |           ref: test-data/v2/basic | ||||||
| @@ -153,7 +126,7 @@ jobs: | |||||||
|         uses: actions/checkout@v2 |         uses: actions/checkout@v2 | ||||||
|  |  | ||||||
|       # Basic checkout using git |       # Basic checkout using git | ||||||
|       - name: Checkout basic |       - name: Basic checkout | ||||||
|         uses: ./ |         uses: ./ | ||||||
|         with: |         with: | ||||||
|           ref: test-data/v2/basic |           ref: test-data/v2/basic | ||||||
| @@ -185,7 +158,7 @@ jobs: | |||||||
|         uses: actions/checkout@v2 |         uses: actions/checkout@v2 | ||||||
|  |  | ||||||
|       # Basic checkout using git |       # Basic checkout using git | ||||||
|       - name: Checkout basic |       - name: Basic checkout | ||||||
|         uses: ./ |         uses: ./ | ||||||
|         with: |         with: | ||||||
|           ref: test-data/v2/basic |           ref: test-data/v2/basic | ||||||
| @@ -198,7 +171,7 @@ jobs: | |||||||
|       # Basic checkout using REST API |       # Basic checkout using REST API | ||||||
|       - name: Override git version |       - name: Override git version | ||||||
|         run: __test__/override-git-version.sh |         run: __test__/override-git-version.sh | ||||||
|       - name: Checkout basic using REST API |       - name: Basic checkout using REST API | ||||||
|         uses: ./ |         uses: ./ | ||||||
|         with: |         with: | ||||||
|           ref: test-data/v2/basic |           ref: test-data/v2/basic | ||||||
|   | |||||||
							
								
								
									
										1
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										1
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							| @@ -1,3 +1,2 @@ | |||||||
| __test__/_temp |  | ||||||
| lib/ | lib/ | ||||||
| node_modules/ | node_modules/ | ||||||
							
								
								
									
										62
									
								
								README.md
									
									
									
									
									
								
							
							
						
						
									
										62
									
								
								README.md
									
									
									
									
									
								
							| @@ -18,7 +18,6 @@ When Git 2.18 or higher is not in your PATH, falls back to the REST API to downl | |||||||
|   - Fetches only a single commit by default |   - Fetches only a single commit by default | ||||||
| - Script authenticated git commands | - Script authenticated git commands | ||||||
|   - Auth token persisted in the local git config |   - Auth token persisted in the local git config | ||||||
| - Supports SSH |  | ||||||
| - Creates a local branch | - Creates a local branch | ||||||
|   - No longer detached HEAD when checking out a branch |   - No longer detached HEAD when checking out a branch | ||||||
| - Improved layout | - Improved layout | ||||||
| @@ -27,6 +26,7 @@ When Git 2.18 or higher is not in your PATH, falls back to the REST API to downl | |||||||
| - Fallback to REST API download | - Fallback to REST API download | ||||||
|   - When Git 2.18 or higher is not in the PATH, the REST API will be used to download the files |   - When Git 2.18 or higher is not in the PATH, the REST API will be used to download the files | ||||||
|   - When using a job container, the container's PATH is used |   - When using a job container, the container's PATH is used | ||||||
|  | - Removed input `submodules` | ||||||
|  |  | ||||||
| Refer [here](https://github.com/actions/checkout/blob/v1/README.md) for previous versions. | Refer [here](https://github.com/actions/checkout/blob/v1/README.md) for previous versions. | ||||||
|  |  | ||||||
| @@ -45,40 +45,14 @@ Refer [here](https://github.com/actions/checkout/blob/v1/README.md) for previous | |||||||
|     # Otherwise, defaults to `master`. |     # Otherwise, defaults to `master`. | ||||||
|     ref: '' |     ref: '' | ||||||
|  |  | ||||||
|     # Personal access token (PAT) used to fetch the repository. The PAT is configured |     # Auth token used to fetch the repository. The token is stored in the local git | ||||||
|     # with the local git config, which enables your scripts to run authenticated git |     # config, which enables your scripts to run authenticated git commands. The | ||||||
|     # commands. The post-job step removes the PAT. |     # post-job step removes the token from the git config. [Learn more about creating | ||||||
|     # |     # and using encrypted secrets](https://help.github.com/en/actions/automating-your-workflow-with-github-actions/creating-and-using-encrypted-secrets) | ||||||
|     # We recommend using a service account with the least permissions necessary. Also |  | ||||||
|     # when generating a new PAT, select the least scopes necessary. |  | ||||||
|     # |  | ||||||
|     # [Learn more about creating and using encrypted secrets](https://help.github.com/en/actions/automating-your-workflow-with-github-actions/creating-and-using-encrypted-secrets) |  | ||||||
|     # |  | ||||||
|     # Default: ${{ github.token }} |     # Default: ${{ github.token }} | ||||||
|     token: '' |     token: '' | ||||||
|  |  | ||||||
|     # SSH key used to fetch the repository. The SSH key is configured with the local |     # Whether to persist the token in the git config | ||||||
|     # git config, which enables your scripts to run authenticated git commands. The |  | ||||||
|     # post-job step removes the SSH key. |  | ||||||
|     # |  | ||||||
|     # We recommend using a service account with the least permissions necessary. |  | ||||||
|     # |  | ||||||
|     # [Learn more about creating and using encrypted secrets](https://help.github.com/en/actions/automating-your-workflow-with-github-actions/creating-and-using-encrypted-secrets) |  | ||||||
|     ssh-key: '' |  | ||||||
|  |  | ||||||
|     # Known hosts in addition to the user and global host key database. The public SSH |  | ||||||
|     # keys for a host may be obtained using the utility `ssh-keyscan`. For example, |  | ||||||
|     # `ssh-keyscan github.com`. The public key for github.com is always implicitly |  | ||||||
|     # added. |  | ||||||
|     ssh-known-hosts: '' |  | ||||||
|  |  | ||||||
|     # Whether to perform strict host key checking. When true, adds the options |  | ||||||
|     # `StrictHostKeyChecking=yes` and `CheckHostIP=no` to the SSH command line. Use |  | ||||||
|     # the input `ssh-known-hosts` to configure additional hosts. |  | ||||||
|     # Default: true |  | ||||||
|     ssh-strict: '' |  | ||||||
|  |  | ||||||
|     # Whether to configure the token or SSH key with the local git config |  | ||||||
|     # Default: true |     # Default: true | ||||||
|     persist-credentials: '' |     persist-credentials: '' | ||||||
|  |  | ||||||
| @@ -96,15 +70,6 @@ Refer [here](https://github.com/actions/checkout/blob/v1/README.md) for previous | |||||||
|     # Whether to download Git-LFS files |     # Whether to download Git-LFS files | ||||||
|     # Default: false |     # Default: false | ||||||
|     lfs: '' |     lfs: '' | ||||||
|  |  | ||||||
|     # Whether to checkout submodules: `true` to checkout submodules or `recursive` to |  | ||||||
|     # recursively checkout submodules. |  | ||||||
|     # |  | ||||||
|     # When the `ssh-key` input is not provided, SSH URLs beginning with |  | ||||||
|     # `git@github.com:` are converted to HTTPS. |  | ||||||
|     # |  | ||||||
|     # Default: false |  | ||||||
|     submodules: '' |  | ||||||
| ``` | ``` | ||||||
| <!-- end usage --> | <!-- end usage --> | ||||||
|  |  | ||||||
| @@ -117,6 +82,7 @@ Refer [here](https://github.com/actions/checkout/blob/v1/README.md) for previous | |||||||
| - [Checkout multiple repos (private)](#Checkout-multiple-repos-private) | - [Checkout multiple repos (private)](#Checkout-multiple-repos-private) | ||||||
| - [Checkout pull request HEAD commit instead of merge commit](#Checkout-pull-request-HEAD-commit-instead-of-merge-commit) | - [Checkout pull request HEAD commit instead of merge commit](#Checkout-pull-request-HEAD-commit-instead-of-merge-commit) | ||||||
| - [Checkout pull request on closed event](#Checkout-pull-request-on-closed-event) | - [Checkout pull request on closed event](#Checkout-pull-request-on-closed-event) | ||||||
|  | - [Checkout submodules](#Checkout-submodules) | ||||||
| - [Fetch all tags](#Fetch-all-tags) | - [Fetch all tags](#Fetch-all-tags) | ||||||
| - [Fetch all branches](#Fetch-all-branches) | - [Fetch all branches](#Fetch-all-branches) | ||||||
| - [Fetch all history for all tags and branches](#Fetch-all-history-for-all-tags-and-branches) | - [Fetch all history for all tags and branches](#Fetch-all-history-for-all-tags-and-branches) | ||||||
| @@ -207,6 +173,20 @@ jobs: | |||||||
|       - uses: actions/checkout@v2 |       - uses: actions/checkout@v2 | ||||||
| ``` | ``` | ||||||
|  |  | ||||||
|  | ## Checkout submodules | ||||||
|  |  | ||||||
|  | ```yaml | ||||||
|  | - uses: actions/checkout@v2 | ||||||
|  | - name: Checkout submodules | ||||||
|  |   shell: bash | ||||||
|  |   run: | | ||||||
|  |     # If your submodules are configured to use SSH instead of HTTPS please uncomment the following line | ||||||
|  |     # git config --global url."https://github.com/".insteadOf "git@github.com:" | ||||||
|  |     auth_header="$(git config --local --get http.https://github.com/.extraheader)" | ||||||
|  |     git submodule sync --recursive | ||||||
|  |     git -c "http.extraheader=$auth_header" -c protocol.version=2 submodule update --init --force --recursive --depth=1 | ||||||
|  | ``` | ||||||
|  |  | ||||||
| ## Fetch all tags | ## Fetch all tags | ||||||
|  |  | ||||||
| ```yaml | ```yaml | ||||||
|   | |||||||
| @@ -1,799 +0,0 @@ | |||||||
| import * as core from '@actions/core' |  | ||||||
| import * as fs from 'fs' |  | ||||||
| import * as gitAuthHelper from '../lib/git-auth-helper' |  | ||||||
| import * as io from '@actions/io' |  | ||||||
| import * as os from 'os' |  | ||||||
| import * as path from 'path' |  | ||||||
| import * as stateHelper from '../lib/state-helper' |  | ||||||
| import {IGitCommandManager} from '../lib/git-command-manager' |  | ||||||
| import {IGitSourceSettings} from '../lib/git-source-settings' |  | ||||||
|  |  | ||||||
| const isWindows = process.platform === 'win32' |  | ||||||
| const testWorkspace = path.join(__dirname, '_temp', 'git-auth-helper') |  | ||||||
| const originalRunnerTemp = process.env['RUNNER_TEMP'] |  | ||||||
| const originalHome = process.env['HOME'] |  | ||||||
| let workspace: string |  | ||||||
| let localGitConfigPath: string |  | ||||||
| let globalGitConfigPath: string |  | ||||||
| let runnerTemp: string |  | ||||||
| let tempHomedir: string |  | ||||||
| let git: IGitCommandManager & {env: {[key: string]: string}} |  | ||||||
| let settings: IGitSourceSettings |  | ||||||
| let sshPath: string |  | ||||||
|  |  | ||||||
| describe('git-auth-helper tests', () => { |  | ||||||
|   beforeAll(async () => { |  | ||||||
|     // SSH |  | ||||||
|     sshPath = await io.which('ssh') |  | ||||||
|  |  | ||||||
|     // Clear test workspace |  | ||||||
|     await io.rmRF(testWorkspace) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   beforeEach(() => { |  | ||||||
|     // Mock setSecret |  | ||||||
|     jest.spyOn(core, 'setSecret').mockImplementation((secret: string) => {}) |  | ||||||
|  |  | ||||||
|     // Mock error/warning/info/debug |  | ||||||
|     jest.spyOn(core, 'error').mockImplementation(jest.fn()) |  | ||||||
|     jest.spyOn(core, 'warning').mockImplementation(jest.fn()) |  | ||||||
|     jest.spyOn(core, 'info').mockImplementation(jest.fn()) |  | ||||||
|     jest.spyOn(core, 'debug').mockImplementation(jest.fn()) |  | ||||||
|  |  | ||||||
|     // Mock state helper |  | ||||||
|     jest.spyOn(stateHelper, 'setSshKeyPath').mockImplementation(jest.fn()) |  | ||||||
|     jest |  | ||||||
|       .spyOn(stateHelper, 'setSshKnownHostsPath') |  | ||||||
|       .mockImplementation(jest.fn()) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   afterEach(() => { |  | ||||||
|     // Unregister mocks |  | ||||||
|     jest.restoreAllMocks() |  | ||||||
|  |  | ||||||
|     // Restore HOME |  | ||||||
|     if (originalHome) { |  | ||||||
|       process.env['HOME'] = originalHome |  | ||||||
|     } else { |  | ||||||
|       delete process.env['HOME'] |  | ||||||
|     } |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   afterAll(() => { |  | ||||||
|     // Restore RUNNER_TEMP |  | ||||||
|     delete process.env['RUNNER_TEMP'] |  | ||||||
|     if (originalRunnerTemp) { |  | ||||||
|       process.env['RUNNER_TEMP'] = originalRunnerTemp |  | ||||||
|     } |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const configureAuth_configuresAuthHeader = |  | ||||||
|     'configureAuth configures auth header' |  | ||||||
|   it(configureAuth_configuresAuthHeader, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(configureAuth_configuresAuthHeader) |  | ||||||
|     expect(settings.authToken).toBeTruthy() // sanity check |  | ||||||
|     const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await authHelper.configureAuth() |  | ||||||
|  |  | ||||||
|     // Assert config |  | ||||||
|     const configContent = ( |  | ||||||
|       await fs.promises.readFile(localGitConfigPath) |  | ||||||
|     ).toString() |  | ||||||
|     const basicCredential = Buffer.from( |  | ||||||
|       `x-access-token:${settings.authToken}`, |  | ||||||
|       'utf8' |  | ||||||
|     ).toString('base64') |  | ||||||
|     expect( |  | ||||||
|       configContent.indexOf( |  | ||||||
|         `http.https://github.com/.extraheader AUTHORIZATION: basic ${basicCredential}` |  | ||||||
|       ) |  | ||||||
|     ).toBeGreaterThanOrEqual(0) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const configureAuth_configuresAuthHeaderEvenWhenPersistCredentialsFalse = |  | ||||||
|     'configureAuth configures auth header even when persist credentials false' |  | ||||||
|   it( |  | ||||||
|     configureAuth_configuresAuthHeaderEvenWhenPersistCredentialsFalse, |  | ||||||
|     async () => { |  | ||||||
|       // Arrange |  | ||||||
|       await setup( |  | ||||||
|         configureAuth_configuresAuthHeaderEvenWhenPersistCredentialsFalse |  | ||||||
|       ) |  | ||||||
|       expect(settings.authToken).toBeTruthy() // sanity check |  | ||||||
|       settings.persistCredentials = false |  | ||||||
|       const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|  |  | ||||||
|       // Act |  | ||||||
|       await authHelper.configureAuth() |  | ||||||
|  |  | ||||||
|       // Assert config |  | ||||||
|       const configContent = ( |  | ||||||
|         await fs.promises.readFile(localGitConfigPath) |  | ||||||
|       ).toString() |  | ||||||
|       expect( |  | ||||||
|         configContent.indexOf( |  | ||||||
|           `http.https://github.com/.extraheader AUTHORIZATION` |  | ||||||
|         ) |  | ||||||
|       ).toBeGreaterThanOrEqual(0) |  | ||||||
|     } |  | ||||||
|   ) |  | ||||||
|  |  | ||||||
|   const configureAuth_copiesUserKnownHosts = |  | ||||||
|     'configureAuth copies user known hosts' |  | ||||||
|   it(configureAuth_copiesUserKnownHosts, async () => { |  | ||||||
|     if (!sshPath) { |  | ||||||
|       process.stdout.write( |  | ||||||
|         `Skipped test "${configureAuth_copiesUserKnownHosts}". Executable 'ssh' not found in the PATH.\n` |  | ||||||
|       ) |  | ||||||
|       return |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // Arange |  | ||||||
|     await setup(configureAuth_copiesUserKnownHosts) |  | ||||||
|     expect(settings.sshKey).toBeTruthy() // sanity check |  | ||||||
|  |  | ||||||
|     // Mock fs.promises.readFile |  | ||||||
|     const realReadFile = fs.promises.readFile |  | ||||||
|     jest.spyOn(fs.promises, 'readFile').mockImplementation( |  | ||||||
|       async (file: any, options: any): Promise<Buffer> => { |  | ||||||
|         const userKnownHostsPath = path.join( |  | ||||||
|           os.homedir(), |  | ||||||
|           '.ssh', |  | ||||||
|           'known_hosts' |  | ||||||
|         ) |  | ||||||
|         if (file === userKnownHostsPath) { |  | ||||||
|           return Buffer.from('some-domain.com ssh-rsa ABCDEF') |  | ||||||
|         } |  | ||||||
|  |  | ||||||
|         return await realReadFile(file, options) |  | ||||||
|       } |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|     await authHelper.configureAuth() |  | ||||||
|  |  | ||||||
|     // Assert known hosts |  | ||||||
|     const actualSshKnownHostsPath = await getActualSshKnownHostsPath() |  | ||||||
|     const actualSshKnownHostsContent = ( |  | ||||||
|       await fs.promises.readFile(actualSshKnownHostsPath) |  | ||||||
|     ).toString() |  | ||||||
|     expect(actualSshKnownHostsContent).toMatch( |  | ||||||
|       /some-domain\.com ssh-rsa ABCDEF/ |  | ||||||
|     ) |  | ||||||
|     expect(actualSshKnownHostsContent).toMatch(/github\.com ssh-rsa AAAAB3N/) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const configureAuth_registersBasicCredentialAsSecret = |  | ||||||
|     'configureAuth registers basic credential as secret' |  | ||||||
|   it(configureAuth_registersBasicCredentialAsSecret, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(configureAuth_registersBasicCredentialAsSecret) |  | ||||||
|     expect(settings.authToken).toBeTruthy() // sanity check |  | ||||||
|     const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await authHelper.configureAuth() |  | ||||||
|  |  | ||||||
|     // Assert secret |  | ||||||
|     const setSecretSpy = core.setSecret as jest.Mock<any, any> |  | ||||||
|     expect(setSecretSpy).toHaveBeenCalledTimes(1) |  | ||||||
|     const expectedSecret = Buffer.from( |  | ||||||
|       `x-access-token:${settings.authToken}`, |  | ||||||
|       'utf8' |  | ||||||
|     ).toString('base64') |  | ||||||
|     expect(setSecretSpy).toHaveBeenCalledWith(expectedSecret) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const setsSshCommandEnvVarWhenPersistCredentialsFalse = |  | ||||||
|     'sets SSH command env var when persist-credentials false' |  | ||||||
|   it(setsSshCommandEnvVarWhenPersistCredentialsFalse, async () => { |  | ||||||
|     if (!sshPath) { |  | ||||||
|       process.stdout.write( |  | ||||||
|         `Skipped test "${setsSshCommandEnvVarWhenPersistCredentialsFalse}". Executable 'ssh' not found in the PATH.\n` |  | ||||||
|       ) |  | ||||||
|       return |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // Arrange |  | ||||||
|     await setup(setsSshCommandEnvVarWhenPersistCredentialsFalse) |  | ||||||
|     settings.persistCredentials = false |  | ||||||
|     const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await authHelper.configureAuth() |  | ||||||
|  |  | ||||||
|     // Assert git env var |  | ||||||
|     const actualKeyPath = await getActualSshKeyPath() |  | ||||||
|     const actualKnownHostsPath = await getActualSshKnownHostsPath() |  | ||||||
|     const expectedSshCommand = `"${sshPath}" -i "$RUNNER_TEMP/${path.basename( |  | ||||||
|       actualKeyPath |  | ||||||
|     )}" -o StrictHostKeyChecking=yes -o CheckHostIP=no -o "UserKnownHostsFile=$RUNNER_TEMP/${path.basename( |  | ||||||
|       actualKnownHostsPath |  | ||||||
|     )}"` |  | ||||||
|     expect(git.setEnvironmentVariable).toHaveBeenCalledWith( |  | ||||||
|       'GIT_SSH_COMMAND', |  | ||||||
|       expectedSshCommand |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Asserty git config |  | ||||||
|     const gitConfigLines = (await fs.promises.readFile(localGitConfigPath)) |  | ||||||
|       .toString() |  | ||||||
|       .split('\n') |  | ||||||
|       .filter(x => x) |  | ||||||
|     expect(gitConfigLines).toHaveLength(1) |  | ||||||
|     expect(gitConfigLines[0]).toMatch(/^http\./) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const configureAuth_setsSshCommandWhenPersistCredentialsTrue = |  | ||||||
|     'sets SSH command when persist-credentials true' |  | ||||||
|   it(configureAuth_setsSshCommandWhenPersistCredentialsTrue, async () => { |  | ||||||
|     if (!sshPath) { |  | ||||||
|       process.stdout.write( |  | ||||||
|         `Skipped test "${configureAuth_setsSshCommandWhenPersistCredentialsTrue}". Executable 'ssh' not found in the PATH.\n` |  | ||||||
|       ) |  | ||||||
|       return |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // Arrange |  | ||||||
|     await setup(configureAuth_setsSshCommandWhenPersistCredentialsTrue) |  | ||||||
|     const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await authHelper.configureAuth() |  | ||||||
|  |  | ||||||
|     // Assert git env var |  | ||||||
|     const actualKeyPath = await getActualSshKeyPath() |  | ||||||
|     const actualKnownHostsPath = await getActualSshKnownHostsPath() |  | ||||||
|     const expectedSshCommand = `"${sshPath}" -i "$RUNNER_TEMP/${path.basename( |  | ||||||
|       actualKeyPath |  | ||||||
|     )}" -o StrictHostKeyChecking=yes -o CheckHostIP=no -o "UserKnownHostsFile=$RUNNER_TEMP/${path.basename( |  | ||||||
|       actualKnownHostsPath |  | ||||||
|     )}"` |  | ||||||
|     expect(git.setEnvironmentVariable).toHaveBeenCalledWith( |  | ||||||
|       'GIT_SSH_COMMAND', |  | ||||||
|       expectedSshCommand |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Asserty git config |  | ||||||
|     expect(git.config).toHaveBeenCalledWith( |  | ||||||
|       'core.sshCommand', |  | ||||||
|       expectedSshCommand |  | ||||||
|     ) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const configureAuth_writesExplicitKnownHosts = 'writes explicit known hosts' |  | ||||||
|   it(configureAuth_writesExplicitKnownHosts, async () => { |  | ||||||
|     if (!sshPath) { |  | ||||||
|       process.stdout.write( |  | ||||||
|         `Skipped test "${configureAuth_writesExplicitKnownHosts}". Executable 'ssh' not found in the PATH.\n` |  | ||||||
|       ) |  | ||||||
|       return |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // Arrange |  | ||||||
|     await setup(configureAuth_writesExplicitKnownHosts) |  | ||||||
|     expect(settings.sshKey).toBeTruthy() // sanity check |  | ||||||
|     settings.sshKnownHosts = 'my-custom-host.com ssh-rsa ABC123' |  | ||||||
|     const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await authHelper.configureAuth() |  | ||||||
|  |  | ||||||
|     // Assert known hosts |  | ||||||
|     const actualSshKnownHostsPath = await getActualSshKnownHostsPath() |  | ||||||
|     const actualSshKnownHostsContent = ( |  | ||||||
|       await fs.promises.readFile(actualSshKnownHostsPath) |  | ||||||
|     ).toString() |  | ||||||
|     expect(actualSshKnownHostsContent).toMatch( |  | ||||||
|       /my-custom-host\.com ssh-rsa ABC123/ |  | ||||||
|     ) |  | ||||||
|     expect(actualSshKnownHostsContent).toMatch(/github\.com ssh-rsa AAAAB3N/) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const configureAuth_writesSshKeyAndImplicitKnownHosts = |  | ||||||
|     'writes SSH key and implicit known hosts' |  | ||||||
|   it(configureAuth_writesSshKeyAndImplicitKnownHosts, async () => { |  | ||||||
|     if (!sshPath) { |  | ||||||
|       process.stdout.write( |  | ||||||
|         `Skipped test "${configureAuth_writesSshKeyAndImplicitKnownHosts}". Executable 'ssh' not found in the PATH.\n` |  | ||||||
|       ) |  | ||||||
|       return |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // Arrange |  | ||||||
|     await setup(configureAuth_writesSshKeyAndImplicitKnownHosts) |  | ||||||
|     expect(settings.sshKey).toBeTruthy() // sanity check |  | ||||||
|     const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await authHelper.configureAuth() |  | ||||||
|  |  | ||||||
|     // Assert SSH key |  | ||||||
|     const actualSshKeyPath = await getActualSshKeyPath() |  | ||||||
|     expect(actualSshKeyPath).toBeTruthy() |  | ||||||
|     const actualSshKeyContent = ( |  | ||||||
|       await fs.promises.readFile(actualSshKeyPath) |  | ||||||
|     ).toString() |  | ||||||
|     expect(actualSshKeyContent).toBe(settings.sshKey + '\n') |  | ||||||
|     if (!isWindows) { |  | ||||||
|       // Assert read/write for user, not group or others. |  | ||||||
|       // Otherwise SSH client will error. |  | ||||||
|       expect((await fs.promises.stat(actualSshKeyPath)).mode & 0o777).toBe( |  | ||||||
|         0o600 |  | ||||||
|       ) |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // Assert known hosts |  | ||||||
|     const actualSshKnownHostsPath = await getActualSshKnownHostsPath() |  | ||||||
|     const actualSshKnownHostsContent = ( |  | ||||||
|       await fs.promises.readFile(actualSshKnownHostsPath) |  | ||||||
|     ).toString() |  | ||||||
|     expect(actualSshKnownHostsContent).toMatch(/github\.com ssh-rsa AAAAB3N/) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const configureGlobalAuth_configuresUrlInsteadOfWhenSshKeyNotSet = |  | ||||||
|     'configureGlobalAuth configures URL insteadOf when SSH key not set' |  | ||||||
|   it(configureGlobalAuth_configuresUrlInsteadOfWhenSshKeyNotSet, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(configureGlobalAuth_configuresUrlInsteadOfWhenSshKeyNotSet) |  | ||||||
|     settings.sshKey = '' |  | ||||||
|     const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await authHelper.configureAuth() |  | ||||||
|     await authHelper.configureGlobalAuth() |  | ||||||
|  |  | ||||||
|     // Assert temporary global config |  | ||||||
|     expect(git.env['HOME']).toBeTruthy() |  | ||||||
|     const configContent = ( |  | ||||||
|       await fs.promises.readFile(path.join(git.env['HOME'], '.gitconfig')) |  | ||||||
|     ).toString() |  | ||||||
|     expect( |  | ||||||
|       configContent.indexOf(`url.https://github.com/.insteadOf git@github.com`) |  | ||||||
|     ).toBeGreaterThanOrEqual(0) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const configureGlobalAuth_copiesGlobalGitConfig = |  | ||||||
|     'configureGlobalAuth copies global git config' |  | ||||||
|   it(configureGlobalAuth_copiesGlobalGitConfig, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(configureGlobalAuth_copiesGlobalGitConfig) |  | ||||||
|     await fs.promises.writeFile(globalGitConfigPath, 'value-from-global-config') |  | ||||||
|     const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await authHelper.configureAuth() |  | ||||||
|     await authHelper.configureGlobalAuth() |  | ||||||
|  |  | ||||||
|     // Assert original global config not altered |  | ||||||
|     let configContent = ( |  | ||||||
|       await fs.promises.readFile(globalGitConfigPath) |  | ||||||
|     ).toString() |  | ||||||
|     expect(configContent).toBe('value-from-global-config') |  | ||||||
|  |  | ||||||
|     // Assert temporary global config |  | ||||||
|     expect(git.env['HOME']).toBeTruthy() |  | ||||||
|     const basicCredential = Buffer.from( |  | ||||||
|       `x-access-token:${settings.authToken}`, |  | ||||||
|       'utf8' |  | ||||||
|     ).toString('base64') |  | ||||||
|     configContent = ( |  | ||||||
|       await fs.promises.readFile(path.join(git.env['HOME'], '.gitconfig')) |  | ||||||
|     ).toString() |  | ||||||
|     expect( |  | ||||||
|       configContent.indexOf('value-from-global-config') |  | ||||||
|     ).toBeGreaterThanOrEqual(0) |  | ||||||
|     expect( |  | ||||||
|       configContent.indexOf( |  | ||||||
|         `http.https://github.com/.extraheader AUTHORIZATION: basic ${basicCredential}` |  | ||||||
|       ) |  | ||||||
|     ).toBeGreaterThanOrEqual(0) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const configureGlobalAuth_createsNewGlobalGitConfigWhenGlobalDoesNotExist = |  | ||||||
|     'configureGlobalAuth creates new git config when global does not exist' |  | ||||||
|   it( |  | ||||||
|     configureGlobalAuth_createsNewGlobalGitConfigWhenGlobalDoesNotExist, |  | ||||||
|     async () => { |  | ||||||
|       // Arrange |  | ||||||
|       await setup( |  | ||||||
|         configureGlobalAuth_createsNewGlobalGitConfigWhenGlobalDoesNotExist |  | ||||||
|       ) |  | ||||||
|       await io.rmRF(globalGitConfigPath) |  | ||||||
|       const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|  |  | ||||||
|       // Act |  | ||||||
|       await authHelper.configureAuth() |  | ||||||
|       await authHelper.configureGlobalAuth() |  | ||||||
|  |  | ||||||
|       // Assert original global config not recreated |  | ||||||
|       try { |  | ||||||
|         await fs.promises.stat(globalGitConfigPath) |  | ||||||
|         throw new Error( |  | ||||||
|           `Did not expect file to exist: '${globalGitConfigPath}'` |  | ||||||
|         ) |  | ||||||
|       } catch (err) { |  | ||||||
|         if (err.code !== 'ENOENT') { |  | ||||||
|           throw err |  | ||||||
|         } |  | ||||||
|       } |  | ||||||
|  |  | ||||||
|       // Assert temporary global config |  | ||||||
|       expect(git.env['HOME']).toBeTruthy() |  | ||||||
|       const basicCredential = Buffer.from( |  | ||||||
|         `x-access-token:${settings.authToken}`, |  | ||||||
|         'utf8' |  | ||||||
|       ).toString('base64') |  | ||||||
|       const configContent = ( |  | ||||||
|         await fs.promises.readFile(path.join(git.env['HOME'], '.gitconfig')) |  | ||||||
|       ).toString() |  | ||||||
|       expect( |  | ||||||
|         configContent.indexOf( |  | ||||||
|           `http.https://github.com/.extraheader AUTHORIZATION: basic ${basicCredential}` |  | ||||||
|         ) |  | ||||||
|       ).toBeGreaterThanOrEqual(0) |  | ||||||
|     } |  | ||||||
|   ) |  | ||||||
|  |  | ||||||
|   const configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsFalseAndSshKeyNotSet = |  | ||||||
|     'configureSubmoduleAuth configures submodules when persist credentials false and SSH key not set' |  | ||||||
|   it( |  | ||||||
|     configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsFalseAndSshKeyNotSet, |  | ||||||
|     async () => { |  | ||||||
|       // Arrange |  | ||||||
|       await setup( |  | ||||||
|         configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsFalseAndSshKeyNotSet |  | ||||||
|       ) |  | ||||||
|       settings.persistCredentials = false |  | ||||||
|       settings.sshKey = '' |  | ||||||
|       const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|       await authHelper.configureAuth() |  | ||||||
|       const mockSubmoduleForeach = git.submoduleForeach as jest.Mock<any, any> |  | ||||||
|       mockSubmoduleForeach.mockClear() // reset calls |  | ||||||
|  |  | ||||||
|       // Act |  | ||||||
|       await authHelper.configureSubmoduleAuth() |  | ||||||
|  |  | ||||||
|       // Assert |  | ||||||
|       expect(mockSubmoduleForeach).toBeCalledTimes(1) |  | ||||||
|       expect(mockSubmoduleForeach.mock.calls[0][0] as string).toMatch( |  | ||||||
|         /unset-all.*insteadOf/ |  | ||||||
|       ) |  | ||||||
|     } |  | ||||||
|   ) |  | ||||||
|  |  | ||||||
|   const configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsFalseAndSshKeySet = |  | ||||||
|     'configureSubmoduleAuth configures submodules when persist credentials false and SSH key set' |  | ||||||
|   it( |  | ||||||
|     configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsFalseAndSshKeySet, |  | ||||||
|     async () => { |  | ||||||
|       if (!sshPath) { |  | ||||||
|         process.stdout.write( |  | ||||||
|           `Skipped test "${configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsFalseAndSshKeySet}". Executable 'ssh' not found in the PATH.\n` |  | ||||||
|         ) |  | ||||||
|         return |  | ||||||
|       } |  | ||||||
|  |  | ||||||
|       // Arrange |  | ||||||
|       await setup( |  | ||||||
|         configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsFalseAndSshKeySet |  | ||||||
|       ) |  | ||||||
|       settings.persistCredentials = false |  | ||||||
|       const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|       await authHelper.configureAuth() |  | ||||||
|       const mockSubmoduleForeach = git.submoduleForeach as jest.Mock<any, any> |  | ||||||
|       mockSubmoduleForeach.mockClear() // reset calls |  | ||||||
|  |  | ||||||
|       // Act |  | ||||||
|       await authHelper.configureSubmoduleAuth() |  | ||||||
|  |  | ||||||
|       // Assert |  | ||||||
|       expect(mockSubmoduleForeach).toHaveBeenCalledTimes(1) |  | ||||||
|       expect(mockSubmoduleForeach.mock.calls[0][0]).toMatch( |  | ||||||
|         /unset-all.*insteadOf/ |  | ||||||
|       ) |  | ||||||
|     } |  | ||||||
|   ) |  | ||||||
|  |  | ||||||
|   const configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsTrueAndSshKeyNotSet = |  | ||||||
|     'configureSubmoduleAuth configures submodules when persist credentials true and SSH key not set' |  | ||||||
|   it( |  | ||||||
|     configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsTrueAndSshKeyNotSet, |  | ||||||
|     async () => { |  | ||||||
|       // Arrange |  | ||||||
|       await setup( |  | ||||||
|         configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsTrueAndSshKeyNotSet |  | ||||||
|       ) |  | ||||||
|       settings.sshKey = '' |  | ||||||
|       const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|       await authHelper.configureAuth() |  | ||||||
|       const mockSubmoduleForeach = git.submoduleForeach as jest.Mock<any, any> |  | ||||||
|       mockSubmoduleForeach.mockClear() // reset calls |  | ||||||
|  |  | ||||||
|       // Act |  | ||||||
|       await authHelper.configureSubmoduleAuth() |  | ||||||
|  |  | ||||||
|       // Assert |  | ||||||
|       expect(mockSubmoduleForeach).toHaveBeenCalledTimes(3) |  | ||||||
|       expect(mockSubmoduleForeach.mock.calls[0][0]).toMatch( |  | ||||||
|         /unset-all.*insteadOf/ |  | ||||||
|       ) |  | ||||||
|       expect(mockSubmoduleForeach.mock.calls[1][0]).toMatch(/http.*extraheader/) |  | ||||||
|       expect(mockSubmoduleForeach.mock.calls[2][0]).toMatch(/url.*insteadOf/) |  | ||||||
|     } |  | ||||||
|   ) |  | ||||||
|  |  | ||||||
|   const configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsTrueAndSshKeySet = |  | ||||||
|     'configureSubmoduleAuth configures submodules when persist credentials true and SSH key set' |  | ||||||
|   it( |  | ||||||
|     configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsTrueAndSshKeySet, |  | ||||||
|     async () => { |  | ||||||
|       if (!sshPath) { |  | ||||||
|         process.stdout.write( |  | ||||||
|           `Skipped test "${configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsTrueAndSshKeySet}". Executable 'ssh' not found in the PATH.\n` |  | ||||||
|         ) |  | ||||||
|         return |  | ||||||
|       } |  | ||||||
|  |  | ||||||
|       // Arrange |  | ||||||
|       await setup( |  | ||||||
|         configureSubmoduleAuth_configuresSubmodulesWhenPersistCredentialsTrueAndSshKeySet |  | ||||||
|       ) |  | ||||||
|       const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|       await authHelper.configureAuth() |  | ||||||
|       const mockSubmoduleForeach = git.submoduleForeach as jest.Mock<any, any> |  | ||||||
|       mockSubmoduleForeach.mockClear() // reset calls |  | ||||||
|  |  | ||||||
|       // Act |  | ||||||
|       await authHelper.configureSubmoduleAuth() |  | ||||||
|  |  | ||||||
|       // Assert |  | ||||||
|       expect(mockSubmoduleForeach).toHaveBeenCalledTimes(3) |  | ||||||
|       expect(mockSubmoduleForeach.mock.calls[0][0]).toMatch( |  | ||||||
|         /unset-all.*insteadOf/ |  | ||||||
|       ) |  | ||||||
|       expect(mockSubmoduleForeach.mock.calls[1][0]).toMatch(/http.*extraheader/) |  | ||||||
|       expect(mockSubmoduleForeach.mock.calls[2][0]).toMatch(/core\.sshCommand/) |  | ||||||
|     } |  | ||||||
|   ) |  | ||||||
|  |  | ||||||
|   const removeAuth_removesSshCommand = 'removeAuth removes SSH command' |  | ||||||
|   it(removeAuth_removesSshCommand, async () => { |  | ||||||
|     if (!sshPath) { |  | ||||||
|       process.stdout.write( |  | ||||||
|         `Skipped test "${removeAuth_removesSshCommand}". Executable 'ssh' not found in the PATH.\n` |  | ||||||
|       ) |  | ||||||
|       return |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // Arrange |  | ||||||
|     await setup(removeAuth_removesSshCommand) |  | ||||||
|     const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|     await authHelper.configureAuth() |  | ||||||
|     let gitConfigContent = ( |  | ||||||
|       await fs.promises.readFile(localGitConfigPath) |  | ||||||
|     ).toString() |  | ||||||
|     expect(gitConfigContent.indexOf('core.sshCommand')).toBeGreaterThanOrEqual( |  | ||||||
|       0 |  | ||||||
|     ) // sanity check |  | ||||||
|     const actualKeyPath = await getActualSshKeyPath() |  | ||||||
|     expect(actualKeyPath).toBeTruthy() |  | ||||||
|     await fs.promises.stat(actualKeyPath) |  | ||||||
|     const actualKnownHostsPath = await getActualSshKnownHostsPath() |  | ||||||
|     expect(actualKnownHostsPath).toBeTruthy() |  | ||||||
|     await fs.promises.stat(actualKnownHostsPath) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await authHelper.removeAuth() |  | ||||||
|  |  | ||||||
|     // Assert git config |  | ||||||
|     gitConfigContent = ( |  | ||||||
|       await fs.promises.readFile(localGitConfigPath) |  | ||||||
|     ).toString() |  | ||||||
|     expect(gitConfigContent.indexOf('core.sshCommand')).toBeLessThan(0) |  | ||||||
|  |  | ||||||
|     // Assert SSH key file |  | ||||||
|     try { |  | ||||||
|       await fs.promises.stat(actualKeyPath) |  | ||||||
|       throw new Error('SSH key should have been deleted') |  | ||||||
|     } catch (err) { |  | ||||||
|       if (err.code !== 'ENOENT') { |  | ||||||
|         throw err |  | ||||||
|       } |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // Assert known hosts file |  | ||||||
|     try { |  | ||||||
|       await fs.promises.stat(actualKnownHostsPath) |  | ||||||
|       throw new Error('SSH known hosts should have been deleted') |  | ||||||
|     } catch (err) { |  | ||||||
|       if (err.code !== 'ENOENT') { |  | ||||||
|         throw err |  | ||||||
|       } |  | ||||||
|     } |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const removeAuth_removesToken = 'removeAuth removes token' |  | ||||||
|   it(removeAuth_removesToken, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(removeAuth_removesToken) |  | ||||||
|     const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|     await authHelper.configureAuth() |  | ||||||
|     let gitConfigContent = ( |  | ||||||
|       await fs.promises.readFile(localGitConfigPath) |  | ||||||
|     ).toString() |  | ||||||
|     expect(gitConfigContent.indexOf('http.')).toBeGreaterThanOrEqual(0) // sanity check |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await authHelper.removeAuth() |  | ||||||
|  |  | ||||||
|     // Assert git config |  | ||||||
|     gitConfigContent = ( |  | ||||||
|       await fs.promises.readFile(localGitConfigPath) |  | ||||||
|     ).toString() |  | ||||||
|     expect(gitConfigContent.indexOf('http.')).toBeLessThan(0) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const removeGlobalAuth_removesOverride = 'removeGlobalAuth removes override' |  | ||||||
|   it(removeGlobalAuth_removesOverride, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(removeGlobalAuth_removesOverride) |  | ||||||
|     const authHelper = gitAuthHelper.createAuthHelper(git, settings) |  | ||||||
|     await authHelper.configureAuth() |  | ||||||
|     await authHelper.configureGlobalAuth() |  | ||||||
|     const homeOverride = git.env['HOME'] // Sanity check |  | ||||||
|     expect(homeOverride).toBeTruthy() |  | ||||||
|     await fs.promises.stat(path.join(git.env['HOME'], '.gitconfig')) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await authHelper.removeGlobalAuth() |  | ||||||
|  |  | ||||||
|     // Assert |  | ||||||
|     expect(git.env['HOME']).toBeUndefined() |  | ||||||
|     try { |  | ||||||
|       await fs.promises.stat(homeOverride) |  | ||||||
|       throw new Error(`Should have been deleted '${homeOverride}'`) |  | ||||||
|     } catch (err) { |  | ||||||
|       if (err.code !== 'ENOENT') { |  | ||||||
|         throw err |  | ||||||
|       } |  | ||||||
|     } |  | ||||||
|   }) |  | ||||||
| }) |  | ||||||
|  |  | ||||||
| async function setup(testName: string): Promise<void> { |  | ||||||
|   testName = testName.replace(/[^a-zA-Z0-9_]+/g, '-') |  | ||||||
|  |  | ||||||
|   // Directories |  | ||||||
|   workspace = path.join(testWorkspace, testName, 'workspace') |  | ||||||
|   runnerTemp = path.join(testWorkspace, testName, 'runner-temp') |  | ||||||
|   tempHomedir = path.join(testWorkspace, testName, 'home-dir') |  | ||||||
|   await fs.promises.mkdir(workspace, {recursive: true}) |  | ||||||
|   await fs.promises.mkdir(runnerTemp, {recursive: true}) |  | ||||||
|   await fs.promises.mkdir(tempHomedir, {recursive: true}) |  | ||||||
|   process.env['RUNNER_TEMP'] = runnerTemp |  | ||||||
|   process.env['HOME'] = tempHomedir |  | ||||||
|  |  | ||||||
|   // Create git config |  | ||||||
|   globalGitConfigPath = path.join(tempHomedir, '.gitconfig') |  | ||||||
|   await fs.promises.writeFile(globalGitConfigPath, '') |  | ||||||
|   localGitConfigPath = path.join(workspace, '.git', 'config') |  | ||||||
|   await fs.promises.mkdir(path.dirname(localGitConfigPath), {recursive: true}) |  | ||||||
|   await fs.promises.writeFile(localGitConfigPath, '') |  | ||||||
|  |  | ||||||
|   git = { |  | ||||||
|     branchDelete: jest.fn(), |  | ||||||
|     branchExists: jest.fn(), |  | ||||||
|     branchList: jest.fn(), |  | ||||||
|     checkout: jest.fn(), |  | ||||||
|     checkoutDetach: jest.fn(), |  | ||||||
|     config: jest.fn( |  | ||||||
|       async (key: string, value: string, globalConfig?: boolean) => { |  | ||||||
|         const configPath = globalConfig |  | ||||||
|           ? path.join(git.env['HOME'] || tempHomedir, '.gitconfig') |  | ||||||
|           : localGitConfigPath |  | ||||||
|         await fs.promises.appendFile(configPath, `\n${key} ${value}`) |  | ||||||
|       } |  | ||||||
|     ), |  | ||||||
|     configExists: jest.fn( |  | ||||||
|       async (key: string, globalConfig?: boolean): Promise<boolean> => { |  | ||||||
|         const configPath = globalConfig |  | ||||||
|           ? path.join(git.env['HOME'] || tempHomedir, '.gitconfig') |  | ||||||
|           : localGitConfigPath |  | ||||||
|         const content = await fs.promises.readFile(configPath) |  | ||||||
|         const lines = content |  | ||||||
|           .toString() |  | ||||||
|           .split('\n') |  | ||||||
|           .filter(x => x) |  | ||||||
|         return lines.some(x => x.startsWith(key)) |  | ||||||
|       } |  | ||||||
|     ), |  | ||||||
|     env: {}, |  | ||||||
|     fetch: jest.fn(), |  | ||||||
|     getWorkingDirectory: jest.fn(() => workspace), |  | ||||||
|     init: jest.fn(), |  | ||||||
|     isDetached: jest.fn(), |  | ||||||
|     lfsFetch: jest.fn(), |  | ||||||
|     lfsInstall: jest.fn(), |  | ||||||
|     log1: jest.fn(), |  | ||||||
|     remoteAdd: jest.fn(), |  | ||||||
|     removeEnvironmentVariable: jest.fn((name: string) => delete git.env[name]), |  | ||||||
|     setEnvironmentVariable: jest.fn((name: string, value: string) => { |  | ||||||
|       git.env[name] = value |  | ||||||
|     }), |  | ||||||
|     submoduleForeach: jest.fn(async () => { |  | ||||||
|       return '' |  | ||||||
|     }), |  | ||||||
|     submoduleSync: jest.fn(), |  | ||||||
|     submoduleUpdate: jest.fn(), |  | ||||||
|     tagExists: jest.fn(), |  | ||||||
|     tryClean: jest.fn(), |  | ||||||
|     tryConfigUnset: jest.fn( |  | ||||||
|       async (key: string, globalConfig?: boolean): Promise<boolean> => { |  | ||||||
|         const configPath = globalConfig |  | ||||||
|           ? path.join(git.env['HOME'] || tempHomedir, '.gitconfig') |  | ||||||
|           : localGitConfigPath |  | ||||||
|         let content = await fs.promises.readFile(configPath) |  | ||||||
|         let lines = content |  | ||||||
|           .toString() |  | ||||||
|           .split('\n') |  | ||||||
|           .filter(x => x) |  | ||||||
|           .filter(x => !x.startsWith(key)) |  | ||||||
|         await fs.promises.writeFile(configPath, lines.join('\n')) |  | ||||||
|         return true |  | ||||||
|       } |  | ||||||
|     ), |  | ||||||
|     tryDisableAutomaticGarbageCollection: jest.fn(), |  | ||||||
|     tryGetFetchUrl: jest.fn(), |  | ||||||
|     tryReset: jest.fn() |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   settings = { |  | ||||||
|     authToken: 'some auth token', |  | ||||||
|     clean: true, |  | ||||||
|     commit: '', |  | ||||||
|     fetchDepth: 1, |  | ||||||
|     lfs: false, |  | ||||||
|     submodules: false, |  | ||||||
|     nestedSubmodules: false, |  | ||||||
|     persistCredentials: true, |  | ||||||
|     ref: 'refs/heads/master', |  | ||||||
|     repositoryName: 'my-repo', |  | ||||||
|     repositoryOwner: 'my-org', |  | ||||||
|     repositoryPath: '', |  | ||||||
|     sshKey: sshPath ? 'some ssh private key' : '', |  | ||||||
|     sshKnownHosts: '', |  | ||||||
|     sshStrict: true |  | ||||||
|   } |  | ||||||
| } |  | ||||||
|  |  | ||||||
| async function getActualSshKeyPath(): Promise<string> { |  | ||||||
|   let actualTempFiles = (await fs.promises.readdir(runnerTemp)) |  | ||||||
|     .sort() |  | ||||||
|     .map(x => path.join(runnerTemp, x)) |  | ||||||
|   if (actualTempFiles.length === 0) { |  | ||||||
|     return '' |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   expect(actualTempFiles).toHaveLength(2) |  | ||||||
|   expect(actualTempFiles[0].endsWith('_known_hosts')).toBeFalsy() |  | ||||||
|   return actualTempFiles[0] |  | ||||||
| } |  | ||||||
|  |  | ||||||
| async function getActualSshKnownHostsPath(): Promise<string> { |  | ||||||
|   let actualTempFiles = (await fs.promises.readdir(runnerTemp)) |  | ||||||
|     .sort() |  | ||||||
|     .map(x => path.join(runnerTemp, x)) |  | ||||||
|   if (actualTempFiles.length === 0) { |  | ||||||
|     return '' |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   expect(actualTempFiles).toHaveLength(2) |  | ||||||
|   expect(actualTempFiles[1].endsWith('_known_hosts')).toBeTruthy() |  | ||||||
|   expect(actualTempFiles[1].startsWith(actualTempFiles[0])).toBeTruthy() |  | ||||||
|   return actualTempFiles[1] |  | ||||||
| } |  | ||||||
| @@ -1,386 +0,0 @@ | |||||||
| import * as core from '@actions/core' |  | ||||||
| import * as fs from 'fs' |  | ||||||
| import * as gitDirectoryHelper from '../lib/git-directory-helper' |  | ||||||
| import * as io from '@actions/io' |  | ||||||
| import * as path from 'path' |  | ||||||
| import {IGitCommandManager} from '../lib/git-command-manager' |  | ||||||
|  |  | ||||||
| const testWorkspace = path.join(__dirname, '_temp', 'git-directory-helper') |  | ||||||
| let repositoryPath: string |  | ||||||
| let repositoryUrl: string |  | ||||||
| let clean: boolean |  | ||||||
| let git: IGitCommandManager |  | ||||||
|  |  | ||||||
| describe('git-directory-helper tests', () => { |  | ||||||
|   beforeAll(async () => { |  | ||||||
|     // Clear test workspace |  | ||||||
|     await io.rmRF(testWorkspace) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   beforeEach(() => { |  | ||||||
|     // Mock error/warning/info/debug |  | ||||||
|     jest.spyOn(core, 'error').mockImplementation(jest.fn()) |  | ||||||
|     jest.spyOn(core, 'warning').mockImplementation(jest.fn()) |  | ||||||
|     jest.spyOn(core, 'info').mockImplementation(jest.fn()) |  | ||||||
|     jest.spyOn(core, 'debug').mockImplementation(jest.fn()) |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   afterEach(() => { |  | ||||||
|     // Unregister mocks |  | ||||||
|     jest.restoreAllMocks() |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const cleansWhenCleanTrue = 'cleans when clean true' |  | ||||||
|   it(cleansWhenCleanTrue, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(cleansWhenCleanTrue) |  | ||||||
|     await fs.promises.writeFile(path.join(repositoryPath, 'my-file'), '') |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await gitDirectoryHelper.prepareExistingDirectory( |  | ||||||
|       git, |  | ||||||
|       repositoryPath, |  | ||||||
|       repositoryUrl, |  | ||||||
|       clean |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Assert |  | ||||||
|     const files = await fs.promises.readdir(repositoryPath) |  | ||||||
|     expect(files.sort()).toEqual(['.git', 'my-file']) |  | ||||||
|     expect(git.tryClean).toHaveBeenCalled() |  | ||||||
|     expect(git.tryReset).toHaveBeenCalled() |  | ||||||
|     expect(core.warning).not.toHaveBeenCalled() |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const checkoutDetachWhenNotDetached = 'checkout detach when not detached' |  | ||||||
|   it(checkoutDetachWhenNotDetached, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(checkoutDetachWhenNotDetached) |  | ||||||
|     await fs.promises.writeFile(path.join(repositoryPath, 'my-file'), '') |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await gitDirectoryHelper.prepareExistingDirectory( |  | ||||||
|       git, |  | ||||||
|       repositoryPath, |  | ||||||
|       repositoryUrl, |  | ||||||
|       clean |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Assert |  | ||||||
|     const files = await fs.promises.readdir(repositoryPath) |  | ||||||
|     expect(files.sort()).toEqual(['.git', 'my-file']) |  | ||||||
|     expect(git.checkoutDetach).toHaveBeenCalled() |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const doesNotCheckoutDetachWhenNotAlreadyDetached = |  | ||||||
|     'does not checkout detach when already detached' |  | ||||||
|   it(doesNotCheckoutDetachWhenNotAlreadyDetached, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(doesNotCheckoutDetachWhenNotAlreadyDetached) |  | ||||||
|     await fs.promises.writeFile(path.join(repositoryPath, 'my-file'), '') |  | ||||||
|     const mockIsDetached = git.isDetached as jest.Mock<any, any> |  | ||||||
|     mockIsDetached.mockImplementation(async () => { |  | ||||||
|       return true |  | ||||||
|     }) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await gitDirectoryHelper.prepareExistingDirectory( |  | ||||||
|       git, |  | ||||||
|       repositoryPath, |  | ||||||
|       repositoryUrl, |  | ||||||
|       clean |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Assert |  | ||||||
|     const files = await fs.promises.readdir(repositoryPath) |  | ||||||
|     expect(files.sort()).toEqual(['.git', 'my-file']) |  | ||||||
|     expect(git.checkoutDetach).not.toHaveBeenCalled() |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const doesNotCleanWhenCleanFalse = 'does not clean when clean false' |  | ||||||
|   it(doesNotCleanWhenCleanFalse, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(doesNotCleanWhenCleanFalse) |  | ||||||
|     clean = false |  | ||||||
|     await fs.promises.writeFile(path.join(repositoryPath, 'my-file'), '') |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await gitDirectoryHelper.prepareExistingDirectory( |  | ||||||
|       git, |  | ||||||
|       repositoryPath, |  | ||||||
|       repositoryUrl, |  | ||||||
|       clean |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Assert |  | ||||||
|     const files = await fs.promises.readdir(repositoryPath) |  | ||||||
|     expect(files.sort()).toEqual(['.git', 'my-file']) |  | ||||||
|     expect(git.isDetached).toHaveBeenCalled() |  | ||||||
|     expect(git.branchList).toHaveBeenCalled() |  | ||||||
|     expect(core.warning).not.toHaveBeenCalled() |  | ||||||
|     expect(git.tryClean).not.toHaveBeenCalled() |  | ||||||
|     expect(git.tryReset).not.toHaveBeenCalled() |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const removesContentsWhenCleanFails = 'removes contents when clean fails' |  | ||||||
|   it(removesContentsWhenCleanFails, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(removesContentsWhenCleanFails) |  | ||||||
|     await fs.promises.writeFile(path.join(repositoryPath, 'my-file'), '') |  | ||||||
|     let mockTryClean = git.tryClean as jest.Mock<any, any> |  | ||||||
|     mockTryClean.mockImplementation(async () => { |  | ||||||
|       return false |  | ||||||
|     }) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await gitDirectoryHelper.prepareExistingDirectory( |  | ||||||
|       git, |  | ||||||
|       repositoryPath, |  | ||||||
|       repositoryUrl, |  | ||||||
|       clean |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Assert |  | ||||||
|     const files = await fs.promises.readdir(repositoryPath) |  | ||||||
|     expect(files).toHaveLength(0) |  | ||||||
|     expect(git.tryClean).toHaveBeenCalled() |  | ||||||
|     expect(core.warning).toHaveBeenCalled() |  | ||||||
|     expect(git.tryReset).not.toHaveBeenCalled() |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const removesContentsWhenDifferentRepositoryUrl = |  | ||||||
|     'removes contents when different repository url' |  | ||||||
|   it(removesContentsWhenDifferentRepositoryUrl, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(removesContentsWhenDifferentRepositoryUrl) |  | ||||||
|     clean = false |  | ||||||
|     await fs.promises.writeFile(path.join(repositoryPath, 'my-file'), '') |  | ||||||
|     const differentRepositoryUrl = |  | ||||||
|       'https://github.com/my-different-org/my-different-repo' |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await gitDirectoryHelper.prepareExistingDirectory( |  | ||||||
|       git, |  | ||||||
|       repositoryPath, |  | ||||||
|       differentRepositoryUrl, |  | ||||||
|       clean |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Assert |  | ||||||
|     const files = await fs.promises.readdir(repositoryPath) |  | ||||||
|     expect(files).toHaveLength(0) |  | ||||||
|     expect(core.warning).not.toHaveBeenCalled() |  | ||||||
|     expect(git.isDetached).not.toHaveBeenCalled() |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const removesContentsWhenNoGitDirectory = |  | ||||||
|     'removes contents when no git directory' |  | ||||||
|   it(removesContentsWhenNoGitDirectory, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(removesContentsWhenNoGitDirectory) |  | ||||||
|     clean = false |  | ||||||
|     await io.rmRF(path.join(repositoryPath, '.git')) |  | ||||||
|     await fs.promises.writeFile(path.join(repositoryPath, 'my-file'), '') |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await gitDirectoryHelper.prepareExistingDirectory( |  | ||||||
|       git, |  | ||||||
|       repositoryPath, |  | ||||||
|       repositoryUrl, |  | ||||||
|       clean |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Assert |  | ||||||
|     const files = await fs.promises.readdir(repositoryPath) |  | ||||||
|     expect(files).toHaveLength(0) |  | ||||||
|     expect(core.warning).not.toHaveBeenCalled() |  | ||||||
|     expect(git.isDetached).not.toHaveBeenCalled() |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const removesContentsWhenResetFails = 'removes contents when reset fails' |  | ||||||
|   it(removesContentsWhenResetFails, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(removesContentsWhenResetFails) |  | ||||||
|     await fs.promises.writeFile(path.join(repositoryPath, 'my-file'), '') |  | ||||||
|     let mockTryReset = git.tryReset as jest.Mock<any, any> |  | ||||||
|     mockTryReset.mockImplementation(async () => { |  | ||||||
|       return false |  | ||||||
|     }) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await gitDirectoryHelper.prepareExistingDirectory( |  | ||||||
|       git, |  | ||||||
|       repositoryPath, |  | ||||||
|       repositoryUrl, |  | ||||||
|       clean |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Assert |  | ||||||
|     const files = await fs.promises.readdir(repositoryPath) |  | ||||||
|     expect(files).toHaveLength(0) |  | ||||||
|     expect(git.tryClean).toHaveBeenCalled() |  | ||||||
|     expect(git.tryReset).toHaveBeenCalled() |  | ||||||
|     expect(core.warning).toHaveBeenCalled() |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const removesContentsWhenUndefinedGitCommandManager = |  | ||||||
|     'removes contents when undefined git command manager' |  | ||||||
|   it(removesContentsWhenUndefinedGitCommandManager, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(removesContentsWhenUndefinedGitCommandManager) |  | ||||||
|     clean = false |  | ||||||
|     await fs.promises.writeFile(path.join(repositoryPath, 'my-file'), '') |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await gitDirectoryHelper.prepareExistingDirectory( |  | ||||||
|       undefined, |  | ||||||
|       repositoryPath, |  | ||||||
|       repositoryUrl, |  | ||||||
|       clean |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Assert |  | ||||||
|     const files = await fs.promises.readdir(repositoryPath) |  | ||||||
|     expect(files).toHaveLength(0) |  | ||||||
|     expect(core.warning).not.toHaveBeenCalled() |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const removesLocalBranches = 'removes local branches' |  | ||||||
|   it(removesLocalBranches, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(removesLocalBranches) |  | ||||||
|     await fs.promises.writeFile(path.join(repositoryPath, 'my-file'), '') |  | ||||||
|     const mockBranchList = git.branchList as jest.Mock<any, any> |  | ||||||
|     mockBranchList.mockImplementation(async (remote: boolean) => { |  | ||||||
|       return remote ? [] : ['local-branch-1', 'local-branch-2'] |  | ||||||
|     }) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await gitDirectoryHelper.prepareExistingDirectory( |  | ||||||
|       git, |  | ||||||
|       repositoryPath, |  | ||||||
|       repositoryUrl, |  | ||||||
|       clean |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Assert |  | ||||||
|     const files = await fs.promises.readdir(repositoryPath) |  | ||||||
|     expect(files.sort()).toEqual(['.git', 'my-file']) |  | ||||||
|     expect(git.branchDelete).toHaveBeenCalledWith(false, 'local-branch-1') |  | ||||||
|     expect(git.branchDelete).toHaveBeenCalledWith(false, 'local-branch-2') |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const removesLockFiles = 'removes lock files' |  | ||||||
|   it(removesLockFiles, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(removesLockFiles) |  | ||||||
|     clean = false |  | ||||||
|     await fs.promises.writeFile( |  | ||||||
|       path.join(repositoryPath, '.git', 'index.lock'), |  | ||||||
|       '' |  | ||||||
|     ) |  | ||||||
|     await fs.promises.writeFile( |  | ||||||
|       path.join(repositoryPath, '.git', 'shallow.lock'), |  | ||||||
|       '' |  | ||||||
|     ) |  | ||||||
|     await fs.promises.writeFile(path.join(repositoryPath, 'my-file'), '') |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await gitDirectoryHelper.prepareExistingDirectory( |  | ||||||
|       git, |  | ||||||
|       repositoryPath, |  | ||||||
|       repositoryUrl, |  | ||||||
|       clean |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Assert |  | ||||||
|     let files = await fs.promises.readdir(path.join(repositoryPath, '.git')) |  | ||||||
|     expect(files).toHaveLength(0) |  | ||||||
|     files = await fs.promises.readdir(repositoryPath) |  | ||||||
|     expect(files.sort()).toEqual(['.git', 'my-file']) |  | ||||||
|     expect(git.isDetached).toHaveBeenCalled() |  | ||||||
|     expect(git.branchList).toHaveBeenCalled() |  | ||||||
|     expect(core.warning).not.toHaveBeenCalled() |  | ||||||
|     expect(git.tryClean).not.toHaveBeenCalled() |  | ||||||
|     expect(git.tryReset).not.toHaveBeenCalled() |  | ||||||
|   }) |  | ||||||
|  |  | ||||||
|   const removesRemoteBranches = 'removes local branches' |  | ||||||
|   it(removesRemoteBranches, async () => { |  | ||||||
|     // Arrange |  | ||||||
|     await setup(removesRemoteBranches) |  | ||||||
|     await fs.promises.writeFile(path.join(repositoryPath, 'my-file'), '') |  | ||||||
|     const mockBranchList = git.branchList as jest.Mock<any, any> |  | ||||||
|     mockBranchList.mockImplementation(async (remote: boolean) => { |  | ||||||
|       return remote ? ['remote-branch-1', 'remote-branch-2'] : [] |  | ||||||
|     }) |  | ||||||
|  |  | ||||||
|     // Act |  | ||||||
|     await gitDirectoryHelper.prepareExistingDirectory( |  | ||||||
|       git, |  | ||||||
|       repositoryPath, |  | ||||||
|       repositoryUrl, |  | ||||||
|       clean |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Assert |  | ||||||
|     const files = await fs.promises.readdir(repositoryPath) |  | ||||||
|     expect(files.sort()).toEqual(['.git', 'my-file']) |  | ||||||
|     expect(git.branchDelete).toHaveBeenCalledWith(true, 'remote-branch-1') |  | ||||||
|     expect(git.branchDelete).toHaveBeenCalledWith(true, 'remote-branch-2') |  | ||||||
|   }) |  | ||||||
| }) |  | ||||||
|  |  | ||||||
| async function setup(testName: string): Promise<void> { |  | ||||||
|   testName = testName.replace(/[^a-zA-Z0-9_]+/g, '-') |  | ||||||
|  |  | ||||||
|   // Repository directory |  | ||||||
|   repositoryPath = path.join(testWorkspace, testName) |  | ||||||
|   await fs.promises.mkdir(path.join(repositoryPath, '.git'), {recursive: true}) |  | ||||||
|  |  | ||||||
|   // Repository URL |  | ||||||
|   repositoryUrl = 'https://github.com/my-org/my-repo' |  | ||||||
|  |  | ||||||
|   // Clean |  | ||||||
|   clean = true |  | ||||||
|  |  | ||||||
|   // Git command manager |  | ||||||
|   git = { |  | ||||||
|     branchDelete: jest.fn(), |  | ||||||
|     branchExists: jest.fn(), |  | ||||||
|     branchList: jest.fn(async () => { |  | ||||||
|       return [] |  | ||||||
|     }), |  | ||||||
|     checkout: jest.fn(), |  | ||||||
|     checkoutDetach: jest.fn(), |  | ||||||
|     config: jest.fn(), |  | ||||||
|     configExists: jest.fn(), |  | ||||||
|     fetch: jest.fn(), |  | ||||||
|     getWorkingDirectory: jest.fn(() => repositoryPath), |  | ||||||
|     init: jest.fn(), |  | ||||||
|     isDetached: jest.fn(), |  | ||||||
|     lfsFetch: jest.fn(), |  | ||||||
|     lfsInstall: jest.fn(), |  | ||||||
|     log1: jest.fn(), |  | ||||||
|     remoteAdd: jest.fn(), |  | ||||||
|     removeEnvironmentVariable: jest.fn(), |  | ||||||
|     setEnvironmentVariable: jest.fn(), |  | ||||||
|     submoduleForeach: jest.fn(), |  | ||||||
|     submoduleSync: jest.fn(), |  | ||||||
|     submoduleUpdate: jest.fn(), |  | ||||||
|     tagExists: jest.fn(), |  | ||||||
|     tryClean: jest.fn(async () => { |  | ||||||
|       return true |  | ||||||
|     }), |  | ||||||
|     tryConfigUnset: jest.fn(), |  | ||||||
|     tryDisableAutomaticGarbageCollection: jest.fn(), |  | ||||||
|     tryGetFetchUrl: jest.fn(async () => { |  | ||||||
|       // Sanity check - this function shouldn't be called when the .git directory doesn't exist |  | ||||||
|       await fs.promises.stat(path.join(repositoryPath, '.git')) |  | ||||||
|       return repositoryUrl |  | ||||||
|     }), |  | ||||||
|     tryReset: jest.fn(async () => { |  | ||||||
|       return true |  | ||||||
|     }) |  | ||||||
|   } |  | ||||||
| } |  | ||||||
| @@ -4,7 +4,7 @@ import * as fsHelper from '../lib/fs-helper' | |||||||
| import * as github from '@actions/github' | import * as github from '@actions/github' | ||||||
| import * as inputHelper from '../lib/input-helper' | import * as inputHelper from '../lib/input-helper' | ||||||
| import * as path from 'path' | import * as path from 'path' | ||||||
| import {IGitSourceSettings} from '../lib/git-source-settings' | import {ISourceSettings} from '../lib/git-source-provider' | ||||||
|  |  | ||||||
| const originalGitHubWorkspace = process.env['GITHUB_WORKSPACE'] | const originalGitHubWorkspace = process.env['GITHUB_WORKSPACE'] | ||||||
| const gitHubWorkspace = path.resolve('/checkout-tests/workspace') | const gitHubWorkspace = path.resolve('/checkout-tests/workspace') | ||||||
| @@ -17,18 +17,12 @@ let originalContext = {...github.context} | |||||||
|  |  | ||||||
| describe('input-helper tests', () => { | describe('input-helper tests', () => { | ||||||
|   beforeAll(() => { |   beforeAll(() => { | ||||||
|     // Mock getInput |     // Mock @actions/core getInput() | ||||||
|     jest.spyOn(core, 'getInput').mockImplementation((name: string) => { |     jest.spyOn(core, 'getInput').mockImplementation((name: string) => { | ||||||
|       return inputs[name] |       return inputs[name] | ||||||
|     }) |     }) | ||||||
|  |  | ||||||
|     // Mock error/warning/info/debug |     // Mock @actions/github context | ||||||
|     jest.spyOn(core, 'error').mockImplementation(jest.fn()) |  | ||||||
|     jest.spyOn(core, 'warning').mockImplementation(jest.fn()) |  | ||||||
|     jest.spyOn(core, 'info').mockImplementation(jest.fn()) |  | ||||||
|     jest.spyOn(core, 'debug').mockImplementation(jest.fn()) |  | ||||||
|  |  | ||||||
|     // Mock github context |  | ||||||
|     jest.spyOn(github.context, 'repo', 'get').mockImplementation(() => { |     jest.spyOn(github.context, 'repo', 'get').mockImplementation(() => { | ||||||
|       return { |       return { | ||||||
|         owner: 'some-owner', |         owner: 'some-owner', | ||||||
| @@ -68,7 +62,7 @@ describe('input-helper tests', () => { | |||||||
|   }) |   }) | ||||||
|  |  | ||||||
|   it('sets defaults', () => { |   it('sets defaults', () => { | ||||||
|     const settings: IGitSourceSettings = inputHelper.getInputs() |     const settings: ISourceSettings = inputHelper.getInputs() | ||||||
|     expect(settings).toBeTruthy() |     expect(settings).toBeTruthy() | ||||||
|     expect(settings.authToken).toBeFalsy() |     expect(settings.authToken).toBeFalsy() | ||||||
|     expect(settings.clean).toBe(true) |     expect(settings.clean).toBe(true) | ||||||
| @@ -86,7 +80,7 @@ describe('input-helper tests', () => { | |||||||
|     let originalRef = github.context.ref |     let originalRef = github.context.ref | ||||||
|     try { |     try { | ||||||
|       github.context.ref = 'some-unqualified-ref' |       github.context.ref = 'some-unqualified-ref' | ||||||
|       const settings: IGitSourceSettings = inputHelper.getInputs() |       const settings: ISourceSettings = inputHelper.getInputs() | ||||||
|       expect(settings).toBeTruthy() |       expect(settings).toBeTruthy() | ||||||
|       expect(settings.commit).toBe('1234567890123456789012345678901234567890') |       expect(settings.commit).toBe('1234567890123456789012345678901234567890') | ||||||
|       expect(settings.ref).toBe('refs/heads/some-unqualified-ref') |       expect(settings.ref).toBe('refs/heads/some-unqualified-ref') | ||||||
| @@ -104,7 +98,7 @@ describe('input-helper tests', () => { | |||||||
|  |  | ||||||
|   it('roots path', () => { |   it('roots path', () => { | ||||||
|     inputs.path = 'some-directory/some-subdirectory' |     inputs.path = 'some-directory/some-subdirectory' | ||||||
|     const settings: IGitSourceSettings = inputHelper.getInputs() |     const settings: ISourceSettings = inputHelper.getInputs() | ||||||
|     expect(settings.repositoryPath).toBe( |     expect(settings.repositoryPath).toBe( | ||||||
|       path.join(gitHubWorkspace, 'some-directory', 'some-subdirectory') |       path.join(gitHubWorkspace, 'some-directory', 'some-subdirectory') | ||||||
|     ) |     ) | ||||||
| @@ -112,22 +106,29 @@ describe('input-helper tests', () => { | |||||||
|  |  | ||||||
|   it('sets correct default ref/sha for other repo', () => { |   it('sets correct default ref/sha for other repo', () => { | ||||||
|     inputs.repository = 'some-owner/some-other-repo' |     inputs.repository = 'some-owner/some-other-repo' | ||||||
|     const settings: IGitSourceSettings = inputHelper.getInputs() |     const settings: ISourceSettings = inputHelper.getInputs() | ||||||
|     expect(settings.ref).toBe('refs/heads/master') |     expect(settings.ref).toBe('refs/heads/master') | ||||||
|     expect(settings.commit).toBeFalsy() |     expect(settings.commit).toBeFalsy() | ||||||
|   }) |   }) | ||||||
|  |  | ||||||
|   it('sets ref to empty when explicit sha', () => { |   it('sets ref to empty when explicit sha', () => { | ||||||
|     inputs.ref = '1111111111222222222233333333334444444444' |     inputs.ref = '1111111111222222222233333333334444444444' | ||||||
|     const settings: IGitSourceSettings = inputHelper.getInputs() |     const settings: ISourceSettings = inputHelper.getInputs() | ||||||
|     expect(settings.ref).toBeFalsy() |     expect(settings.ref).toBeFalsy() | ||||||
|     expect(settings.commit).toBe('1111111111222222222233333333334444444444') |     expect(settings.commit).toBe('1111111111222222222233333333334444444444') | ||||||
|   }) |   }) | ||||||
|  |  | ||||||
|   it('sets sha to empty when explicit ref', () => { |   it('sets sha to empty when explicit ref', () => { | ||||||
|     inputs.ref = 'refs/heads/some-other-ref' |     inputs.ref = 'refs/heads/some-other-ref' | ||||||
|     const settings: IGitSourceSettings = inputHelper.getInputs() |     const settings: ISourceSettings = inputHelper.getInputs() | ||||||
|     expect(settings.ref).toBe('refs/heads/some-other-ref') |     expect(settings.ref).toBe('refs/heads/some-other-ref') | ||||||
|     expect(settings.commit).toBeFalsy() |     expect(settings.commit).toBeFalsy() | ||||||
|   }) |   }) | ||||||
|  |  | ||||||
|  |   it('gives good error message for submodules input', () => { | ||||||
|  |     inputs.submodules = 'true' | ||||||
|  |     assert.throws(() => { | ||||||
|  |       inputHelper.getInputs() | ||||||
|  |     }, /The input 'submodules' is not supported/) | ||||||
|  |   }) | ||||||
| }) | }) | ||||||
|   | |||||||
| @@ -1,11 +0,0 @@ | |||||||
| #!/bin/bash |  | ||||||
|  |  | ||||||
| if [ ! -f "./submodules-false/regular-file.txt" ]; then |  | ||||||
|     echo "Expected regular file does not exist" |  | ||||||
|     exit 1 |  | ||||||
| fi |  | ||||||
|  |  | ||||||
| if [ -f "./submodules-false/submodule-level-1/submodule-file.txt" ]; then |  | ||||||
|     echo "Unexpected submodule file exists" |  | ||||||
|     exit 1 |  | ||||||
| fi |  | ||||||
							
								
								
									
										11
									
								
								__test__/verify-submodules-not-checked-out.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										11
									
								
								__test__/verify-submodules-not-checked-out.sh
									
									
									
									
									
										Executable file
									
								
							| @@ -0,0 +1,11 @@ | |||||||
|  | #!/bin/bash | ||||||
|  |  | ||||||
|  | if [ ! -f "./submodules-not-checked-out/regular-file.txt" ]; then | ||||||
|  |     echo "Expected regular file does not exist" | ||||||
|  |     exit 1 | ||||||
|  | fi | ||||||
|  |  | ||||||
|  | if [ -f "./submodules-not-checked-out/submodule-level-1/submodule-file.txt" ]; then | ||||||
|  |     echo "Unexpected submodule file exists" | ||||||
|  |     exit 1 | ||||||
|  | fi | ||||||
| @@ -1,26 +0,0 @@ | |||||||
| #!/bin/bash |  | ||||||
|  |  | ||||||
| if [ ! -f "./submodules-recursive/regular-file.txt" ]; then |  | ||||||
|     echo "Expected regular file does not exist" |  | ||||||
|     exit 1 |  | ||||||
| fi |  | ||||||
|  |  | ||||||
| if [ ! -f "./submodules-recursive/submodule-level-1/submodule-file.txt" ]; then |  | ||||||
|     echo "Expected submodule file does not exist" |  | ||||||
|     exit 1 |  | ||||||
| fi |  | ||||||
|  |  | ||||||
| if [ ! -f "./submodules-recursive/submodule-level-1/submodule-level-2/nested-submodule-file.txt" ]; then |  | ||||||
|     echo "Expected nested submodule file does not exists" |  | ||||||
|     exit 1 |  | ||||||
| fi |  | ||||||
|  |  | ||||||
| echo "Testing persisted credential" |  | ||||||
| pushd ./submodules-recursive/submodule-level-1/submodule-level-2 |  | ||||||
| git config --local --name-only --get-regexp http.+extraheader && git fetch |  | ||||||
| if [ "$?" != "0" ]; then |  | ||||||
|     echo "Failed to validate persisted credential" |  | ||||||
|     popd |  | ||||||
|     exit 1 |  | ||||||
| fi |  | ||||||
| popd |  | ||||||
| @@ -1,26 +0,0 @@ | |||||||
| #!/bin/bash |  | ||||||
|  |  | ||||||
| if [ ! -f "./submodules-true/regular-file.txt" ]; then |  | ||||||
|     echo "Expected regular file does not exist" |  | ||||||
|     exit 1 |  | ||||||
| fi |  | ||||||
|  |  | ||||||
| if [ ! -f "./submodules-true/submodule-level-1/submodule-file.txt" ]; then |  | ||||||
|     echo "Expected submodule file does not exist" |  | ||||||
|     exit 1 |  | ||||||
| fi |  | ||||||
|  |  | ||||||
| if [ -f "./submodules-true/submodule-level-1/submodule-level-2/nested-submodule-file.txt" ]; then |  | ||||||
|     echo "Unexpected nested submodule file exists" |  | ||||||
|     exit 1 |  | ||||||
| fi |  | ||||||
|  |  | ||||||
| echo "Testing persisted credential" |  | ||||||
| pushd ./submodules-true/submodule-level-1 |  | ||||||
| git config --local --name-only --get-regexp http.+extraheader && git fetch |  | ||||||
| if [ "$?" != "0" ]; then |  | ||||||
|     echo "Failed to validate persisted credential" |  | ||||||
|     popd |  | ||||||
|     exit 1 |  | ||||||
| fi |  | ||||||
| popd |  | ||||||
							
								
								
									
										48
									
								
								action.yml
									
									
									
									
									
								
							
							
						
						
									
										48
									
								
								action.yml
									
									
									
									
									
								
							| @@ -11,42 +11,13 @@ inputs: | |||||||
|       event.  Otherwise, defaults to `master`. |       event.  Otherwise, defaults to `master`. | ||||||
|   token: |   token: | ||||||
|     description: > |     description: > | ||||||
|       Personal access token (PAT) used to fetch the repository. The PAT is configured |       Auth token used to fetch the repository. The token is stored in the local | ||||||
|       with the local git config, which enables your scripts to run authenticated git |  | ||||||
|       commands. The post-job step removes the PAT. |  | ||||||
|  |  | ||||||
|  |  | ||||||
|       We recommend using a service account with the least permissions necessary. |  | ||||||
|       Also when generating a new PAT, select the least scopes necessary. |  | ||||||
|  |  | ||||||
|  |  | ||||||
|       [Learn more about creating and using encrypted secrets](https://help.github.com/en/actions/automating-your-workflow-with-github-actions/creating-and-using-encrypted-secrets) |  | ||||||
|     default: ${{ github.token }} |  | ||||||
|   ssh-key: |  | ||||||
|     description: > |  | ||||||
|       SSH key used to fetch the repository. The SSH key is configured with the local |  | ||||||
|       git config, which enables your scripts to run authenticated git commands. |       git config, which enables your scripts to run authenticated git commands. | ||||||
|       The post-job step removes the SSH key. |       The post-job step removes the token from the git config. [Learn more about | ||||||
|  |       creating and using encrypted secrets](https://help.github.com/en/actions/automating-your-workflow-with-github-actions/creating-and-using-encrypted-secrets) | ||||||
|  |     default: ${{ github.token }} | ||||||
|       We recommend using a service account with the least permissions necessary. |  | ||||||
|  |  | ||||||
|  |  | ||||||
|       [Learn more about creating and using |  | ||||||
|       encrypted secrets](https://help.github.com/en/actions/automating-your-workflow-with-github-actions/creating-and-using-encrypted-secrets) |  | ||||||
|   ssh-known-hosts: |  | ||||||
|     description: > |  | ||||||
|       Known hosts in addition to the user and global host key database. The public |  | ||||||
|       SSH keys for a host may be obtained using the utility `ssh-keyscan`. For example, |  | ||||||
|       `ssh-keyscan github.com`. The public key for github.com is always implicitly added. |  | ||||||
|   ssh-strict: |  | ||||||
|     description: > |  | ||||||
|       Whether to perform strict host key checking. When true, adds the options `StrictHostKeyChecking=yes` |  | ||||||
|       and `CheckHostIP=no` to the SSH command line. Use the input `ssh-known-hosts` to |  | ||||||
|       configure additional hosts. |  | ||||||
|     default: true |  | ||||||
|   persist-credentials: |   persist-credentials: | ||||||
|     description: 'Whether to configure the token or SSH key with the local git config' |     description: 'Whether to persist the token in the git config' | ||||||
|     default: true |     default: true | ||||||
|   path: |   path: | ||||||
|     description: 'Relative path under $GITHUB_WORKSPACE to place the repository' |     description: 'Relative path under $GITHUB_WORKSPACE to place the repository' | ||||||
| @@ -59,15 +30,6 @@ inputs: | |||||||
|   lfs: |   lfs: | ||||||
|     description: 'Whether to download Git-LFS files' |     description: 'Whether to download Git-LFS files' | ||||||
|     default: false |     default: false | ||||||
|   submodules: |  | ||||||
|     description: > |  | ||||||
|       Whether to checkout submodules: `true` to checkout submodules or `recursive` to |  | ||||||
|       recursively checkout submodules. |  | ||||||
|  |  | ||||||
|  |  | ||||||
|       When the `ssh-key` input is not provided, SSH URLs beginning with `git@github.com:` are |  | ||||||
|       converted to HTTPS. |  | ||||||
|     default: false |  | ||||||
| runs: | runs: | ||||||
|   using: node12 |   using: node12 | ||||||
|   main: dist/index.js |   main: dist/index.js | ||||||
|   | |||||||
| @@ -27,42 +27,13 @@ We want to take this opportunity to make behavioral changes, from v1. This docum | |||||||
|       event.  Otherwise, defaults to `master`. |       event.  Otherwise, defaults to `master`. | ||||||
|   token: |   token: | ||||||
|     description: > |     description: > | ||||||
|       Personal access token (PAT) used to fetch the repository. The PAT is configured |       Auth token used to fetch the repository. The token is stored in the local | ||||||
|       with the local git config, which enables your scripts to run authenticated git |  | ||||||
|       commands. The post-job step removes the PAT. |  | ||||||
|  |  | ||||||
|  |  | ||||||
|       We recommend using a service account with the least permissions necessary. |  | ||||||
|       Also when generating a new PAT, select the least scopes necessary. |  | ||||||
|  |  | ||||||
|  |  | ||||||
|       [Learn more about creating and using encrypted secrets](https://help.github.com/en/actions/automating-your-workflow-with-github-actions/creating-and-using-encrypted-secrets) |  | ||||||
|     default: ${{ github.token }} |  | ||||||
|   ssh-key: |  | ||||||
|     description: > |  | ||||||
|       SSH key used to fetch the repository. The SSH key is configured with the local |  | ||||||
|       git config, which enables your scripts to run authenticated git commands. |       git config, which enables your scripts to run authenticated git commands. | ||||||
|       The post-job step removes the SSH key. |       The post-job step removes the token from the git config. [Learn more about | ||||||
|  |       creating and using encrypted secrets](https://help.github.com/en/actions/automating-your-workflow-with-github-actions/creating-and-using-encrypted-secrets) | ||||||
|  |     default: ${{ github.token }} | ||||||
|       We recommend using a service account with the least permissions necessary. |  | ||||||
|  |  | ||||||
|  |  | ||||||
|       [Learn more about creating and using |  | ||||||
|       encrypted secrets](https://help.github.com/en/actions/automating-your-workflow-with-github-actions/creating-and-using-encrypted-secrets) |  | ||||||
|   ssh-known-hosts: |  | ||||||
|     description: > |  | ||||||
|       Known hosts in addition to the user and global host key database. The public |  | ||||||
|       SSH keys for a host may be obtained using the utility `ssh-keyscan`. For example, |  | ||||||
|       `ssh-keyscan github.com`. The public key for github.com is always implicitly added. |  | ||||||
|   ssh-strict: |  | ||||||
|     description: > |  | ||||||
|       Whether to perform strict host key checking. When true, adds the options `StrictHostKeyChecking=yes` |  | ||||||
|       and `CheckHostIP=no` to the SSH command line. Use the input `ssh-known-hosts` to |  | ||||||
|       configure additional hosts. |  | ||||||
|     default: true |  | ||||||
|   persist-credentials: |   persist-credentials: | ||||||
|     description: 'Whether to configure the token or SSH key with the local git config' |     description: 'Whether to persist the token in the git config' | ||||||
|     default: true |     default: true | ||||||
|   path: |   path: | ||||||
|     description: 'Relative path under $GITHUB_WORKSPACE to place the repository' |     description: 'Relative path under $GITHUB_WORKSPACE to place the repository' | ||||||
| @@ -72,24 +43,21 @@ We want to take this opportunity to make behavioral changes, from v1. This docum | |||||||
|   fetch-depth: |   fetch-depth: | ||||||
|     description: 'Number of commits to fetch. 0 indicates all history.' |     description: 'Number of commits to fetch. 0 indicates all history.' | ||||||
|     default: 1 |     default: 1 | ||||||
|  |   fetch-refs: | ||||||
|  |     description: > | ||||||
|  |       Additional refs to fetch: `branches`, `tags`, `pr-base`, or `all`. | ||||||
|  |       Combinations are also accepted. For example: `branches, tags` | ||||||
|  |     default: '' | ||||||
|   lfs: |   lfs: | ||||||
|     description: 'Whether to download Git-LFS files' |     description: 'Whether to download Git-LFS files' | ||||||
|     default: false |     default: false | ||||||
|   submodules: |  | ||||||
|     description: > |  | ||||||
|       Whether to checkout submodules: `true` to checkout submodules or `recursive` to |  | ||||||
|       recursively checkout submodules. |  | ||||||
|  |  | ||||||
|  |  | ||||||
|       When the `ssh-key` input is not provided, SSH URLs beginning with `git@github.com:` are |  | ||||||
|       converted to HTTPS. |  | ||||||
|     default: false |  | ||||||
| ``` | ``` | ||||||
|  |  | ||||||
| Note: | Note: | ||||||
| - SSH support is new | - `fetch-refs` is new | ||||||
| - `persist-credentials` is new | - `persist-credentials` is new | ||||||
| - `path` behavior is different (refer [below](#path) for details) | - `path` behavior is different (refer [below](#path) for details) | ||||||
|  | - `submodules` was removed (error if specified; add later if needed) | ||||||
|  |  | ||||||
| ### Fallback to GitHub API | ### Fallback to GitHub API | ||||||
|  |  | ||||||
| @@ -97,57 +65,23 @@ When a sufficient version of git is not in the PATH, fallback to the [web API](h | |||||||
|  |  | ||||||
| Note: | Note: | ||||||
| - LFS files are not included in the archive. Therefore fail if LFS is set to true. | - LFS files are not included in the archive. Therefore fail if LFS is set to true. | ||||||
| - Submodules are also not included in the archive. | - Submodules are also not included in the archive. However submodules are not supported by checkout v2 anyway. | ||||||
|  |  | ||||||
| ### Persist credentials | ### Persist credentials | ||||||
|  |  | ||||||
| The credentials will be persisted on disk. This will allow users to script authenticated git commands, like `git fetch`. | Persist the token in the git config (http.extraheader). This will allow users to script authenticated git commands, like `git fetch`. | ||||||
|  |  | ||||||
| A post script will remove the credentials (cleanup for self-hosted). | A post script will remove the credentials from the git config (cleanup for self-hosted). | ||||||
|  |  | ||||||
| Users may opt-out by specifying `persist-credentials: false` | Users may opt-out by specifying `persist-credentials: false` | ||||||
|  |  | ||||||
| Note: | Note: | ||||||
| - Users scripting `git commit` may need to set the username and email. The service does not provide any reasonable default value. Users can add `git config user.name <NAME>` and `git config user.email <EMAIL>`. We will document this guidance. | - Users scripting `git commit` may need to set the username and email. The service does not provide any reasonable default value. Users can add `git config user.name <NAME>` and `git config user.email <EMAIL>`. We will document this guidance. | ||||||
|  | - The auth header (stored in the repo's git config), is scoped to all of github `http.https://github.com/.extraheader` | ||||||
| #### PAT |  | ||||||
|  |  | ||||||
| When using the `${{github.token}}` or a PAT, the token will be persisted in the local git config. The config key `http.https://github.com/.extraheader` enables an auth header to be specified on all authenticated commands `AUTHORIZATION: basic <BASE64_U:P>`. |  | ||||||
|  |  | ||||||
| Note: |  | ||||||
| - The auth header is scoped to all of github `http.https://github.com/.extraheader` |  | ||||||
|   - Additional public remotes also just work. |   - Additional public remotes also just work. | ||||||
|   - If users want to authenticate to an additional private remote, they should provide the `token` input. |   - If users want to authenticate to an additional private remote, they should provide the `token` input. | ||||||
|  |   - Lines up if we add submodule support in the future. Don't need to worry about calculating relative URLs. Just works, although needs to be persisted in each submodule git config. | ||||||
| #### SSH key |   - Users opt out of persisted credentials (`persist-credentials: false`), or can script the removal themselves (`git config --unset-all http.https://github.com/.extraheader`). | ||||||
|  |  | ||||||
| The SSH key will be written to disk under the `$RUNNER_TEMP` directory. The SSH key will |  | ||||||
| be removed by the action's post-job hook. Additionally, RUNNER_TEMP is cleared by the |  | ||||||
| runner between jobs. |  | ||||||
|  |  | ||||||
| The SSH key must be written with strict file permissions. The SSH client requires the file |  | ||||||
| to be read/write for the user, and not accessible by others. |  | ||||||
|  |  | ||||||
| The user host key database (`~/.ssh/known_hosts`) will be copied to a unique file under |  | ||||||
| `$RUNNER_TEMP`. And values from the input `ssh-known-hosts` will be added to the file. |  | ||||||
|  |  | ||||||
| The SSH command will be overridden for the local git config: |  | ||||||
|  |  | ||||||
| ```sh |  | ||||||
| git config core.sshCommand 'ssh -i "$RUNNER_TEMP/path-to-ssh-key" -o StrictHostKeyChecking=yes -o CheckHostIP=no -o "UserKnownHostsFile=$RUNNER_TEMP/path-to-known-hosts"' |  | ||||||
| ``` |  | ||||||
|  |  | ||||||
| When the input `ssh-strict` is set to `false`, the options `CheckHostIP` and `StrictHostKeyChecking` will not be overridden. |  | ||||||
|  |  | ||||||
| Note: |  | ||||||
| - When `ssh-strict` is set to `true` (default), the SSH option `CheckHostIP` can safely be disabled. |  | ||||||
|   Strict host checking verifies the server's public key. Therefore, IP verification is unnecessary |  | ||||||
|   and noisy. For example: |  | ||||||
|   > Warning: Permanently added the RSA host key for IP address '140.82.113.4' to the list of known hosts. |  | ||||||
| - Since GIT_SSH_COMMAND overrides core.sshCommand, temporarily set the env var when fetching the repo. When creds |  | ||||||
|   are persisted, core.sshCommand is leveraged to avoid multiple checkout steps stomping over each other. |  | ||||||
| - Modify actions/runner to mount RUNNER_TEMP to enable scripting authenticated git commands from a container action. |  | ||||||
| - Refer [here](https://linux.die.net/man/5/ssh_config) for SSH config details. |  | ||||||
|  |  | ||||||
| ### Fetch behavior | ### Fetch behavior | ||||||
|  |  | ||||||
| @@ -157,6 +91,8 @@ If a SHA isn't available (e.g. multi repo), then fetch only the specified ref wi | |||||||
|  |  | ||||||
| The input `fetch-depth` can be used to control the depth. | The input `fetch-depth` can be used to control the depth. | ||||||
|  |  | ||||||
|  | The input `fetch-refs` can be used to fetch additional refs. | ||||||
|  |  | ||||||
| Note: | Note: | ||||||
| - Fetching a single commit is supported by Git wire protocol version 2. The git client uses protocol version 0 by default. The desired protocol version can be overridden in the git config or on the fetch command line invocation (`-c protocol.version=2`). We will override on the fetch command line, for transparency. | - Fetching a single commit is supported by Git wire protocol version 2. The git client uses protocol version 0 by default. The desired protocol version can be overridden in the git config or on the fetch command line invocation (`-c protocol.version=2`). We will override on the fetch command line, for transparency. | ||||||
| - Git client version 2.18+ (released June 2018) is required for wire protocol version 2. | - Git client version 2.18+ (released June 2018) is required for wire protocol version 2. | ||||||
| @@ -251,17 +187,6 @@ A better solution is: | |||||||
|  |  | ||||||
| Given a source file path, walk up the directories until the first `.git/config` is found. Check if it matches the self repo (`url = https://github.com/OWNER/REPO`). If not, drop the source file path. | Given a source file path, walk up the directories until the first `.git/config` is found. Check if it matches the self repo (`url = https://github.com/OWNER/REPO`). If not, drop the source file path. | ||||||
|  |  | ||||||
| ### Submodules |  | ||||||
|  |  | ||||||
| With both PAT and SSH key support, we should be able to provide frictionless support for |  | ||||||
| submodules scenarios: recursive, non-recursive, relative submodule paths. |  | ||||||
|  |  | ||||||
| When fetching submodules, follow the `fetch-depth` settings. |  | ||||||
|  |  | ||||||
| Also when fetching submodules, if the `ssh-key` input is not provided then convert SSH URLs to HTTPS: `-c url."https://github.com/".insteadOf "git@github.com:"` |  | ||||||
|  |  | ||||||
| Credentials will be persisted in the submodules local git config too. |  | ||||||
|  |  | ||||||
| ### Port to typescript | ### Port to typescript | ||||||
|  |  | ||||||
| The checkout action should be a typescript action on the GitHub graph, for the following reasons: | The checkout action should be a typescript action on the GitHub graph, for the following reasons: | ||||||
|   | |||||||
							
								
								
									
										768
									
								
								dist/index.js
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										768
									
								
								dist/index.js
									
									
									
									
										vendored
									
									
								
							| @@ -1266,46 +1266,6 @@ const windowsRelease = release => { | |||||||
| module.exports = windowsRelease; | module.exports = windowsRelease; | ||||||
|  |  | ||||||
|  |  | ||||||
| /***/ }), |  | ||||||
|  |  | ||||||
| /***/ 81: |  | ||||||
| /***/ (function(__unusedmodule, exports, __webpack_require__) { |  | ||||||
|  |  | ||||||
| "use strict"; |  | ||||||
|  |  | ||||||
| var __importStar = (this && this.__importStar) || function (mod) { |  | ||||||
|     if (mod && mod.__esModule) return mod; |  | ||||||
|     var result = {}; |  | ||||||
|     if (mod != null) for (var k in mod) if (Object.hasOwnProperty.call(mod, k)) result[k] = mod[k]; |  | ||||||
|     result["default"] = mod; |  | ||||||
|     return result; |  | ||||||
| }; |  | ||||||
| Object.defineProperty(exports, "__esModule", { value: true }); |  | ||||||
| const assert = __importStar(__webpack_require__(357)); |  | ||||||
| const url_1 = __webpack_require__(835); |  | ||||||
| function getApiUrl() { |  | ||||||
|     return process.env['GITHUB_API_URL'] || 'https://api.github.com'; |  | ||||||
| } |  | ||||||
| exports.getApiUrl = getApiUrl; |  | ||||||
| function getFetchUrl(settings) { |  | ||||||
|     assert.ok(settings.repositoryOwner, 'settings.repositoryOwner must be defined'); |  | ||||||
|     assert.ok(settings.repositoryName, 'settings.repositoryName must be defined'); |  | ||||||
|     const serviceUrl = getServerUrl(); |  | ||||||
|     const encodedOwner = encodeURIComponent(settings.repositoryOwner); |  | ||||||
|     const encodedName = encodeURIComponent(settings.repositoryName); |  | ||||||
|     if (settings.sshKey) { |  | ||||||
|         return `git@${serviceUrl.hostname}:${encodedOwner}/${encodedName}.git`; |  | ||||||
|     } |  | ||||||
|     // "origin" is SCHEME://HOSTNAME[:PORT] |  | ||||||
|     return `${serviceUrl.origin}/${encodedOwner}/${encodedName}`; |  | ||||||
| } |  | ||||||
| exports.getFetchUrl = getFetchUrl; |  | ||||||
| function getServerUrl() { |  | ||||||
|     return new url_1.URL(process.env['GITHUB_URL'] || 'https://github.com'); |  | ||||||
| } |  | ||||||
| exports.getServerUrl = getServerUrl; |  | ||||||
|  |  | ||||||
|  |  | ||||||
| /***/ }), | /***/ }), | ||||||
|  |  | ||||||
| /***/ 87: | /***/ 87: | ||||||
| @@ -2661,14 +2621,6 @@ exports.IsPost = !!process.env['STATE_isPost']; | |||||||
|  * The repository path for the POST action. The value is empty during the MAIN action. |  * The repository path for the POST action. The value is empty during the MAIN action. | ||||||
|  */ |  */ | ||||||
| exports.RepositoryPath = process.env['STATE_repositoryPath'] || ''; | exports.RepositoryPath = process.env['STATE_repositoryPath'] || ''; | ||||||
| /** |  | ||||||
|  * The SSH key path for the POST action. The value is empty during the MAIN action. |  | ||||||
|  */ |  | ||||||
| exports.SshKeyPath = process.env['STATE_sshKeyPath'] || ''; |  | ||||||
| /** |  | ||||||
|  * The SSH known hosts path for the POST action. The value is empty during the MAIN action. |  | ||||||
|  */ |  | ||||||
| exports.SshKnownHostsPath = process.env['STATE_sshKnownHostsPath'] || ''; |  | ||||||
| /** | /** | ||||||
|  * Save the repository path so the POST action can retrieve the value. |  * Save the repository path so the POST action can retrieve the value. | ||||||
|  */ |  */ | ||||||
| @@ -2676,20 +2628,6 @@ function setRepositoryPath(repositoryPath) { | |||||||
|     coreCommand.issueCommand('save-state', { name: 'repositoryPath' }, repositoryPath); |     coreCommand.issueCommand('save-state', { name: 'repositoryPath' }, repositoryPath); | ||||||
| } | } | ||||||
| exports.setRepositoryPath = setRepositoryPath; | exports.setRepositoryPath = setRepositoryPath; | ||||||
| /** |  | ||||||
|  * Save the SSH key path so the POST action can retrieve the value. |  | ||||||
|  */ |  | ||||||
| function setSshKeyPath(sshKeyPath) { |  | ||||||
|     coreCommand.issueCommand('save-state', { name: 'sshKeyPath' }, sshKeyPath); |  | ||||||
| } |  | ||||||
| exports.setSshKeyPath = setSshKeyPath; |  | ||||||
| /** |  | ||||||
|  * Save the SSH known hosts path so the POST action can retrieve the value. |  | ||||||
|  */ |  | ||||||
| function setSshKnownHostsPath(sshKnownHostsPath) { |  | ||||||
|     coreCommand.issueCommand('save-state', { name: 'sshKnownHostsPath' }, sshKnownHostsPath); |  | ||||||
| } |  | ||||||
| exports.setSshKnownHostsPath = setSshKnownHostsPath; |  | ||||||
| // Publish a variable so that when the POST action runs, it can determine it should run the cleanup logic. | // Publish a variable so that when the POST action runs, it can determine it should run the cleanup logic. | ||||||
| // This is necessary since we don't have a separate entry point. | // This is necessary since we don't have a separate entry point. | ||||||
| if (!exports.IsPost) { | if (!exports.IsPost) { | ||||||
| @@ -5113,300 +5051,6 @@ function coerce (version) { | |||||||
| } | } | ||||||
|  |  | ||||||
|  |  | ||||||
| /***/ }), |  | ||||||
|  |  | ||||||
| /***/ 287: |  | ||||||
| /***/ (function(__unusedmodule, exports, __webpack_require__) { |  | ||||||
|  |  | ||||||
| "use strict"; |  | ||||||
|  |  | ||||||
| var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) { |  | ||||||
|     function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); } |  | ||||||
|     return new (P || (P = Promise))(function (resolve, reject) { |  | ||||||
|         function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } } |  | ||||||
|         function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } } |  | ||||||
|         function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); } |  | ||||||
|         step((generator = generator.apply(thisArg, _arguments || [])).next()); |  | ||||||
|     }); |  | ||||||
| }; |  | ||||||
| var __importStar = (this && this.__importStar) || function (mod) { |  | ||||||
|     if (mod && mod.__esModule) return mod; |  | ||||||
|     var result = {}; |  | ||||||
|     if (mod != null) for (var k in mod) if (Object.hasOwnProperty.call(mod, k)) result[k] = mod[k]; |  | ||||||
|     result["default"] = mod; |  | ||||||
|     return result; |  | ||||||
| }; |  | ||||||
| var __importDefault = (this && this.__importDefault) || function (mod) { |  | ||||||
|     return (mod && mod.__esModule) ? mod : { "default": mod }; |  | ||||||
| }; |  | ||||||
| Object.defineProperty(exports, "__esModule", { value: true }); |  | ||||||
| const assert = __importStar(__webpack_require__(357)); |  | ||||||
| const core = __importStar(__webpack_require__(470)); |  | ||||||
| const exec = __importStar(__webpack_require__(986)); |  | ||||||
| const fs = __importStar(__webpack_require__(747)); |  | ||||||
| const io = __importStar(__webpack_require__(1)); |  | ||||||
| const os = __importStar(__webpack_require__(87)); |  | ||||||
| const path = __importStar(__webpack_require__(622)); |  | ||||||
| const regexpHelper = __importStar(__webpack_require__(528)); |  | ||||||
| const stateHelper = __importStar(__webpack_require__(153)); |  | ||||||
| const urlHelper = __importStar(__webpack_require__(81)); |  | ||||||
| const v4_1 = __importDefault(__webpack_require__(826)); |  | ||||||
| const IS_WINDOWS = process.platform === 'win32'; |  | ||||||
| const SSH_COMMAND_KEY = 'core.sshCommand'; |  | ||||||
| function createAuthHelper(git, settings) { |  | ||||||
|     return new GitAuthHelper(git, settings); |  | ||||||
| } |  | ||||||
| exports.createAuthHelper = createAuthHelper; |  | ||||||
| class GitAuthHelper { |  | ||||||
|     constructor(gitCommandManager, gitSourceSettings) { |  | ||||||
|         this.sshCommand = ''; |  | ||||||
|         this.sshKeyPath = ''; |  | ||||||
|         this.sshKnownHostsPath = ''; |  | ||||||
|         this.temporaryHomePath = ''; |  | ||||||
|         this.git = gitCommandManager; |  | ||||||
|         this.settings = gitSourceSettings || {}; |  | ||||||
|         // Token auth header |  | ||||||
|         const serverUrl = urlHelper.getServerUrl(); |  | ||||||
|         this.tokenConfigKey = `http.${serverUrl.origin}/.extraheader`; // "origin" is SCHEME://HOSTNAME[:PORT] |  | ||||||
|         const basicCredential = Buffer.from(`x-access-token:${this.settings.authToken}`, 'utf8').toString('base64'); |  | ||||||
|         core.setSecret(basicCredential); |  | ||||||
|         this.tokenPlaceholderConfigValue = `AUTHORIZATION: basic ***`; |  | ||||||
|         this.tokenConfigValue = `AUTHORIZATION: basic ${basicCredential}`; |  | ||||||
|         // Instead of SSH URL |  | ||||||
|         this.insteadOfKey = `url.${serverUrl.origin}/.insteadOf`; // "origin" is SCHEME://HOSTNAME[:PORT] |  | ||||||
|         this.insteadOfValue = `git@${serverUrl.hostname}:`; |  | ||||||
|     } |  | ||||||
|     configureAuth() { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             // Remove possible previous values |  | ||||||
|             yield this.removeAuth(); |  | ||||||
|             // Configure new values |  | ||||||
|             yield this.configureSsh(); |  | ||||||
|             yield this.configureToken(); |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
|     configureGlobalAuth() { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             // Create a temp home directory |  | ||||||
|             const runnerTemp = process.env['RUNNER_TEMP'] || ''; |  | ||||||
|             assert.ok(runnerTemp, 'RUNNER_TEMP is not defined'); |  | ||||||
|             const uniqueId = v4_1.default(); |  | ||||||
|             this.temporaryHomePath = path.join(runnerTemp, uniqueId); |  | ||||||
|             yield fs.promises.mkdir(this.temporaryHomePath, { recursive: true }); |  | ||||||
|             // Copy the global git config |  | ||||||
|             const gitConfigPath = path.join(process.env['HOME'] || os.homedir(), '.gitconfig'); |  | ||||||
|             const newGitConfigPath = path.join(this.temporaryHomePath, '.gitconfig'); |  | ||||||
|             let configExists = false; |  | ||||||
|             try { |  | ||||||
|                 yield fs.promises.stat(gitConfigPath); |  | ||||||
|                 configExists = true; |  | ||||||
|             } |  | ||||||
|             catch (err) { |  | ||||||
|                 if (err.code !== 'ENOENT') { |  | ||||||
|                     throw err; |  | ||||||
|                 } |  | ||||||
|             } |  | ||||||
|             if (configExists) { |  | ||||||
|                 core.info(`Copying '${gitConfigPath}' to '${newGitConfigPath}'`); |  | ||||||
|                 yield io.cp(gitConfigPath, newGitConfigPath); |  | ||||||
|             } |  | ||||||
|             else { |  | ||||||
|                 yield fs.promises.writeFile(newGitConfigPath, ''); |  | ||||||
|             } |  | ||||||
|             try { |  | ||||||
|                 // Override HOME |  | ||||||
|                 core.info(`Temporarily overriding HOME='${this.temporaryHomePath}' before making global git config changes`); |  | ||||||
|                 this.git.setEnvironmentVariable('HOME', this.temporaryHomePath); |  | ||||||
|                 // Configure the token |  | ||||||
|                 yield this.configureToken(newGitConfigPath, true); |  | ||||||
|                 // Configure HTTPS instead of SSH |  | ||||||
|                 yield this.git.tryConfigUnset(this.insteadOfKey, true); |  | ||||||
|                 if (!this.settings.sshKey) { |  | ||||||
|                     yield this.git.config(this.insteadOfKey, this.insteadOfValue, true); |  | ||||||
|                 } |  | ||||||
|             } |  | ||||||
|             catch (err) { |  | ||||||
|                 // Unset in case somehow written to the real global config |  | ||||||
|                 core.info('Encountered an error when attempting to configure token. Attempting unconfigure.'); |  | ||||||
|                 yield this.git.tryConfigUnset(this.tokenConfigKey, true); |  | ||||||
|                 throw err; |  | ||||||
|             } |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
|     configureSubmoduleAuth() { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             // Remove possible previous HTTPS instead of SSH |  | ||||||
|             yield this.removeGitConfig(this.insteadOfKey, true); |  | ||||||
|             if (this.settings.persistCredentials) { |  | ||||||
|                 // Configure a placeholder value. This approach avoids the credential being captured |  | ||||||
|                 // by process creation audit events, which are commonly logged. For more information, |  | ||||||
|                 // refer to https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/component-updates/command-line-process-auditing |  | ||||||
|                 const output = yield this.git.submoduleForeach(`git config --local '${this.tokenConfigKey}' '${this.tokenPlaceholderConfigValue}' && git config --local --show-origin --name-only --get-regexp remote.origin.url`, this.settings.nestedSubmodules); |  | ||||||
|                 // Replace the placeholder |  | ||||||
|                 const configPaths = output.match(/(?<=(^|\n)file:)[^\t]+(?=\tremote\.origin\.url)/g) || []; |  | ||||||
|                 for (const configPath of configPaths) { |  | ||||||
|                     core.debug(`Replacing token placeholder in '${configPath}'`); |  | ||||||
|                     this.replaceTokenPlaceholder(configPath); |  | ||||||
|                 } |  | ||||||
|                 if (this.settings.sshKey) { |  | ||||||
|                     // Configure core.sshCommand |  | ||||||
|                     yield this.git.submoduleForeach(`git config --local '${SSH_COMMAND_KEY}' '${this.sshCommand}'`, this.settings.nestedSubmodules); |  | ||||||
|                 } |  | ||||||
|                 else { |  | ||||||
|                     // Configure HTTPS instead of SSH |  | ||||||
|                     yield this.git.submoduleForeach(`git config --local '${this.insteadOfKey}' '${this.insteadOfValue}'`, this.settings.nestedSubmodules); |  | ||||||
|                 } |  | ||||||
|             } |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
|     removeAuth() { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             yield this.removeSsh(); |  | ||||||
|             yield this.removeToken(); |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
|     removeGlobalAuth() { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             core.debug(`Unsetting HOME override`); |  | ||||||
|             this.git.removeEnvironmentVariable('HOME'); |  | ||||||
|             yield io.rmRF(this.temporaryHomePath); |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
|     configureSsh() { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             if (!this.settings.sshKey) { |  | ||||||
|                 return; |  | ||||||
|             } |  | ||||||
|             // Write key |  | ||||||
|             const runnerTemp = process.env['RUNNER_TEMP'] || ''; |  | ||||||
|             assert.ok(runnerTemp, 'RUNNER_TEMP is not defined'); |  | ||||||
|             const uniqueId = v4_1.default(); |  | ||||||
|             this.sshKeyPath = path.join(runnerTemp, uniqueId); |  | ||||||
|             stateHelper.setSshKeyPath(this.sshKeyPath); |  | ||||||
|             yield fs.promises.mkdir(runnerTemp, { recursive: true }); |  | ||||||
|             yield fs.promises.writeFile(this.sshKeyPath, this.settings.sshKey.trim() + '\n', { mode: 0o600 }); |  | ||||||
|             // Remove inherited permissions on Windows |  | ||||||
|             if (IS_WINDOWS) { |  | ||||||
|                 const icacls = yield io.which('icacls.exe'); |  | ||||||
|                 yield exec.exec(`"${icacls}" "${this.sshKeyPath}" /grant:r "${process.env['USERDOMAIN']}\\${process.env['USERNAME']}:F"`); |  | ||||||
|                 yield exec.exec(`"${icacls}" "${this.sshKeyPath}" /inheritance:r`); |  | ||||||
|             } |  | ||||||
|             // Write known hosts |  | ||||||
|             const userKnownHostsPath = path.join(os.homedir(), '.ssh', 'known_hosts'); |  | ||||||
|             let userKnownHosts = ''; |  | ||||||
|             try { |  | ||||||
|                 userKnownHosts = (yield fs.promises.readFile(userKnownHostsPath)).toString(); |  | ||||||
|             } |  | ||||||
|             catch (err) { |  | ||||||
|                 if (err.code !== 'ENOENT') { |  | ||||||
|                     throw err; |  | ||||||
|                 } |  | ||||||
|             } |  | ||||||
|             let knownHosts = ''; |  | ||||||
|             if (userKnownHosts) { |  | ||||||
|                 knownHosts += `# Begin from ${userKnownHostsPath}\n${userKnownHosts}\n# End from ${userKnownHostsPath}\n`; |  | ||||||
|             } |  | ||||||
|             if (this.settings.sshKnownHosts) { |  | ||||||
|                 knownHosts += `# Begin from input known hosts\n${this.settings.sshKnownHosts}\n# end from input known hosts\n`; |  | ||||||
|             } |  | ||||||
|             knownHosts += `# Begin implicitly added github.com\ngithub.com ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAq2A7hRGmdnm9tUDbO9IDSwBK6TbQa+PXYPCPy6rbTrTtw7PHkccKrpp0yVhp5HdEIcKr6pLlVDBfOLX9QUsyCOV0wzfjIJNlGEYsdlLJizHhbn2mUjvSAHQqZETYP81eFzLQNnPHt4EVVUh7VfDESU84KezmD5QlWpXLmvU31/yMf+Se8xhHTvKSCZIFImWwoG6mbUoWf9nzpIoaSjB+weqqUUmpaaasXVal72J+UX2B+2RPW3RcT0eOzQgqlJL3RKrTJvdsjE3JEAvGq3lGHSZXy28G3skua2SmVi/w4yCE6gbODqnTWlg7+wC604ydGXA8VJiS5ap43JXiUFFAaQ==\n# End implicitly added github.com\n`; |  | ||||||
|             this.sshKnownHostsPath = path.join(runnerTemp, `${uniqueId}_known_hosts`); |  | ||||||
|             stateHelper.setSshKnownHostsPath(this.sshKnownHostsPath); |  | ||||||
|             yield fs.promises.writeFile(this.sshKnownHostsPath, knownHosts); |  | ||||||
|             // Configure GIT_SSH_COMMAND |  | ||||||
|             const sshPath = yield io.which('ssh', true); |  | ||||||
|             this.sshCommand = `"${sshPath}" -i "$RUNNER_TEMP/${path.basename(this.sshKeyPath)}"`; |  | ||||||
|             if (this.settings.sshStrict) { |  | ||||||
|                 this.sshCommand += ' -o StrictHostKeyChecking=yes -o CheckHostIP=no'; |  | ||||||
|             } |  | ||||||
|             this.sshCommand += ` -o "UserKnownHostsFile=$RUNNER_TEMP/${path.basename(this.sshKnownHostsPath)}"`; |  | ||||||
|             core.info(`Temporarily overriding GIT_SSH_COMMAND=${this.sshCommand}`); |  | ||||||
|             this.git.setEnvironmentVariable('GIT_SSH_COMMAND', this.sshCommand); |  | ||||||
|             // Configure core.sshCommand |  | ||||||
|             if (this.settings.persistCredentials) { |  | ||||||
|                 yield this.git.config(SSH_COMMAND_KEY, this.sshCommand); |  | ||||||
|             } |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
|     configureToken(configPath, globalConfig) { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             // Validate args |  | ||||||
|             assert.ok((configPath && globalConfig) || (!configPath && !globalConfig), 'Unexpected configureToken parameter combinations'); |  | ||||||
|             // Default config path |  | ||||||
|             if (!configPath && !globalConfig) { |  | ||||||
|                 configPath = path.join(this.git.getWorkingDirectory(), '.git', 'config'); |  | ||||||
|             } |  | ||||||
|             // Configure a placeholder value. This approach avoids the credential being captured |  | ||||||
|             // by process creation audit events, which are commonly logged. For more information, |  | ||||||
|             // refer to https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/component-updates/command-line-process-auditing |  | ||||||
|             yield this.git.config(this.tokenConfigKey, this.tokenPlaceholderConfigValue, globalConfig); |  | ||||||
|             // Replace the placeholder |  | ||||||
|             yield this.replaceTokenPlaceholder(configPath || ''); |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
|     replaceTokenPlaceholder(configPath) { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             assert.ok(configPath, 'configPath is not defined'); |  | ||||||
|             let content = (yield fs.promises.readFile(configPath)).toString(); |  | ||||||
|             const placeholderIndex = content.indexOf(this.tokenPlaceholderConfigValue); |  | ||||||
|             if (placeholderIndex < 0 || |  | ||||||
|                 placeholderIndex != content.lastIndexOf(this.tokenPlaceholderConfigValue)) { |  | ||||||
|                 throw new Error(`Unable to replace auth placeholder in ${configPath}`); |  | ||||||
|             } |  | ||||||
|             assert.ok(this.tokenConfigValue, 'tokenConfigValue is not defined'); |  | ||||||
|             content = content.replace(this.tokenPlaceholderConfigValue, this.tokenConfigValue); |  | ||||||
|             yield fs.promises.writeFile(configPath, content); |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
|     removeSsh() { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             // SSH key |  | ||||||
|             const keyPath = this.sshKeyPath || stateHelper.SshKeyPath; |  | ||||||
|             if (keyPath) { |  | ||||||
|                 try { |  | ||||||
|                     yield io.rmRF(keyPath); |  | ||||||
|                 } |  | ||||||
|                 catch (err) { |  | ||||||
|                     core.debug(err.message); |  | ||||||
|                     core.warning(`Failed to remove SSH key '${keyPath}'`); |  | ||||||
|                 } |  | ||||||
|             } |  | ||||||
|             // SSH known hosts |  | ||||||
|             const knownHostsPath = this.sshKnownHostsPath || stateHelper.SshKnownHostsPath; |  | ||||||
|             if (knownHostsPath) { |  | ||||||
|                 try { |  | ||||||
|                     yield io.rmRF(knownHostsPath); |  | ||||||
|                 } |  | ||||||
|                 catch (_a) { |  | ||||||
|                     // Intentionally empty |  | ||||||
|                 } |  | ||||||
|             } |  | ||||||
|             // SSH command |  | ||||||
|             yield this.removeGitConfig(SSH_COMMAND_KEY); |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
|     removeToken() { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             // HTTP extra header |  | ||||||
|             yield this.removeGitConfig(this.tokenConfigKey); |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
|     removeGitConfig(configKey, submoduleOnly = false) { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             if (!submoduleOnly) { |  | ||||||
|                 if ((yield this.git.configExists(configKey)) && |  | ||||||
|                     !(yield this.git.tryConfigUnset(configKey))) { |  | ||||||
|                     // Load the config contents |  | ||||||
|                     core.warning(`Failed to remove '${configKey}' from the git config`); |  | ||||||
|                 } |  | ||||||
|             } |  | ||||||
|             const pattern = regexpHelper.escape(configKey); |  | ||||||
|             yield this.git.submoduleForeach(`git config --local --name-only --get-regexp '${pattern}' && git config --local --unset-all '${configKey}' || :`, true); |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
| } |  | ||||||
|  |  | ||||||
|  |  | ||||||
| /***/ }), | /***/ }), | ||||||
|  |  | ||||||
| /***/ 289: | /***/ 289: | ||||||
| @@ -5436,18 +5080,17 @@ const exec = __importStar(__webpack_require__(986)); | |||||||
| const fshelper = __importStar(__webpack_require__(618)); | const fshelper = __importStar(__webpack_require__(618)); | ||||||
| const io = __importStar(__webpack_require__(1)); | const io = __importStar(__webpack_require__(1)); | ||||||
| const path = __importStar(__webpack_require__(622)); | const path = __importStar(__webpack_require__(622)); | ||||||
| const regexpHelper = __importStar(__webpack_require__(528)); |  | ||||||
| const retryHelper = __importStar(__webpack_require__(587)); | const retryHelper = __importStar(__webpack_require__(587)); | ||||||
| const git_version_1 = __webpack_require__(559); | const git_version_1 = __webpack_require__(559); | ||||||
| // Auth header not supported before 2.9 | // Auth header not supported before 2.9 | ||||||
| // Wire protocol v2 not supported before 2.18 | // Wire protocol v2 not supported before 2.18 | ||||||
| exports.MinimumGitVersion = new git_version_1.GitVersion('2.18'); | exports.MinimumGitVersion = new git_version_1.GitVersion('2.18'); | ||||||
| function createCommandManager(workingDirectory, lfs) { | function CreateCommandManager(workingDirectory, lfs) { | ||||||
|     return __awaiter(this, void 0, void 0, function* () { |     return __awaiter(this, void 0, void 0, function* () { | ||||||
|         return yield GitCommandManager.createCommandManager(workingDirectory, lfs); |         return yield GitCommandManager.createCommandManager(workingDirectory, lfs); | ||||||
|     }); |     }); | ||||||
| } | } | ||||||
| exports.createCommandManager = createCommandManager; | exports.CreateCommandManager = CreateCommandManager; | ||||||
| class GitCommandManager { | class GitCommandManager { | ||||||
|     // Private constructor; use createCommandManager() |     // Private constructor; use createCommandManager() | ||||||
|     constructor() { |     constructor() { | ||||||
| @@ -5528,26 +5171,17 @@ class GitCommandManager { | |||||||
|             yield this.execGit(args); |             yield this.execGit(args); | ||||||
|         }); |         }); | ||||||
|     } |     } | ||||||
|     config(configKey, configValue, globalConfig) { |     config(configKey, configValue) { | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |         return __awaiter(this, void 0, void 0, function* () { | ||||||
|             yield this.execGit([ |             yield this.execGit(['config', '--local', configKey, configValue]); | ||||||
|                 'config', |  | ||||||
|                 globalConfig ? '--global' : '--local', |  | ||||||
|                 configKey, |  | ||||||
|                 configValue |  | ||||||
|             ]); |  | ||||||
|         }); |         }); | ||||||
|     } |     } | ||||||
|     configExists(configKey, globalConfig) { |     configExists(configKey) { | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |         return __awaiter(this, void 0, void 0, function* () { | ||||||
|             const pattern = regexpHelper.escape(configKey); |             const pattern = configKey.replace(/[^a-zA-Z0-9_]/g, x => { | ||||||
|             const output = yield this.execGit([ |                 return `\\${x}`; | ||||||
|                 'config', |             }); | ||||||
|                 globalConfig ? '--global' : '--local', |             const output = yield this.execGit(['config', '--local', '--name-only', '--get-regexp', pattern], true); | ||||||
|                 '--name-only', |  | ||||||
|                 '--get-regexp', |  | ||||||
|                 pattern |  | ||||||
|             ], true); |  | ||||||
|             return output.exitCode === 0; |             return output.exitCode === 0; | ||||||
|         }); |         }); | ||||||
|     } |     } | ||||||
| @@ -5617,45 +5251,6 @@ class GitCommandManager { | |||||||
|             yield this.execGit(['remote', 'add', remoteName, remoteUrl]); |             yield this.execGit(['remote', 'add', remoteName, remoteUrl]); | ||||||
|         }); |         }); | ||||||
|     } |     } | ||||||
|     removeEnvironmentVariable(name) { |  | ||||||
|         delete this.gitEnv[name]; |  | ||||||
|     } |  | ||||||
|     setEnvironmentVariable(name, value) { |  | ||||||
|         this.gitEnv[name] = value; |  | ||||||
|     } |  | ||||||
|     submoduleForeach(command, recursive) { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             const args = ['submodule', 'foreach']; |  | ||||||
|             if (recursive) { |  | ||||||
|                 args.push('--recursive'); |  | ||||||
|             } |  | ||||||
|             args.push(command); |  | ||||||
|             const output = yield this.execGit(args); |  | ||||||
|             return output.stdout; |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
|     submoduleSync(recursive) { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             const args = ['submodule', 'sync']; |  | ||||||
|             if (recursive) { |  | ||||||
|                 args.push('--recursive'); |  | ||||||
|             } |  | ||||||
|             yield this.execGit(args); |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
|     submoduleUpdate(fetchDepth, recursive) { |  | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|             const args = ['-c', 'protocol.version=2']; |  | ||||||
|             args.push('submodule', 'update', '--init', '--force'); |  | ||||||
|             if (fetchDepth > 0) { |  | ||||||
|                 args.push(`--depth=${fetchDepth}`); |  | ||||||
|             } |  | ||||||
|             if (recursive) { |  | ||||||
|                 args.push('--recursive'); |  | ||||||
|             } |  | ||||||
|             yield this.execGit(args); |  | ||||||
|         }); |  | ||||||
|     } |  | ||||||
|     tagExists(pattern) { |     tagExists(pattern) { | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |         return __awaiter(this, void 0, void 0, function* () { | ||||||
|             const output = yield this.execGit(['tag', '--list', pattern]); |             const output = yield this.execGit(['tag', '--list', pattern]); | ||||||
| @@ -5668,14 +5263,9 @@ class GitCommandManager { | |||||||
|             return output.exitCode === 0; |             return output.exitCode === 0; | ||||||
|         }); |         }); | ||||||
|     } |     } | ||||||
|     tryConfigUnset(configKey, globalConfig) { |     tryConfigUnset(configKey) { | ||||||
|         return __awaiter(this, void 0, void 0, function* () { |         return __awaiter(this, void 0, void 0, function* () { | ||||||
|             const output = yield this.execGit([ |             const output = yield this.execGit(['config', '--local', '--unset-all', configKey], true); | ||||||
|                 'config', |  | ||||||
|                 globalConfig ? '--global' : '--local', |  | ||||||
|                 '--unset-all', |  | ||||||
|                 configKey |  | ||||||
|             ], true); |  | ||||||
|             return output.exitCode === 0; |             return output.exitCode === 0; | ||||||
|         }); |         }); | ||||||
|     } |     } | ||||||
| @@ -5830,21 +5420,21 @@ var __importStar = (this && this.__importStar) || function (mod) { | |||||||
| }; | }; | ||||||
| Object.defineProperty(exports, "__esModule", { value: true }); | Object.defineProperty(exports, "__esModule", { value: true }); | ||||||
| const core = __importStar(__webpack_require__(470)); | const core = __importStar(__webpack_require__(470)); | ||||||
|  | const fs = __importStar(__webpack_require__(747)); | ||||||
| const fsHelper = __importStar(__webpack_require__(618)); | const fsHelper = __importStar(__webpack_require__(618)); | ||||||
| const gitAuthHelper = __importStar(__webpack_require__(287)); |  | ||||||
| const gitCommandManager = __importStar(__webpack_require__(289)); | const gitCommandManager = __importStar(__webpack_require__(289)); | ||||||
| const gitDirectoryHelper = __importStar(__webpack_require__(438)); |  | ||||||
| const githubApiHelper = __importStar(__webpack_require__(464)); | const githubApiHelper = __importStar(__webpack_require__(464)); | ||||||
| const io = __importStar(__webpack_require__(1)); | const io = __importStar(__webpack_require__(1)); | ||||||
| const path = __importStar(__webpack_require__(622)); | const path = __importStar(__webpack_require__(622)); | ||||||
| const refHelper = __importStar(__webpack_require__(227)); | const refHelper = __importStar(__webpack_require__(227)); | ||||||
| const stateHelper = __importStar(__webpack_require__(153)); | const stateHelper = __importStar(__webpack_require__(153)); | ||||||
| const urlHelper = __importStar(__webpack_require__(81)); | const serverUrl = 'https://github.com/'; | ||||||
|  | const authConfigKey = `http.${serverUrl}.extraheader`; | ||||||
| function getSource(settings) { | function getSource(settings) { | ||||||
|     return __awaiter(this, void 0, void 0, function* () { |     return __awaiter(this, void 0, void 0, function* () { | ||||||
|         // Repository URL |         // Repository URL | ||||||
|         core.info(`Syncing repository: ${settings.repositoryOwner}/${settings.repositoryName}`); |         core.info(`Syncing repository: ${settings.repositoryOwner}/${settings.repositoryName}`); | ||||||
|         const repositoryUrl = urlHelper.getFetchUrl(settings); |         const repositoryUrl = `https://github.com/${encodeURIComponent(settings.repositoryOwner)}/${encodeURIComponent(settings.repositoryName)}`; | ||||||
|         // Remove conflicting file path |         // Remove conflicting file path | ||||||
|         if (fsHelper.fileExistsSync(settings.repositoryPath)) { |         if (fsHelper.fileExistsSync(settings.repositoryPath)) { | ||||||
|             yield io.rmRF(settings.repositoryPath); |             yield io.rmRF(settings.repositoryPath); | ||||||
| @@ -5856,106 +5446,58 @@ function getSource(settings) { | |||||||
|             yield io.mkdirP(settings.repositoryPath); |             yield io.mkdirP(settings.repositoryPath); | ||||||
|         } |         } | ||||||
|         // Git command manager |         // Git command manager | ||||||
|         core.startGroup('Getting Git version info'); |  | ||||||
|         const git = yield getGitCommandManager(settings); |         const git = yield getGitCommandManager(settings); | ||||||
|         core.endGroup(); |  | ||||||
|         // Prepare existing directory, otherwise recreate |         // Prepare existing directory, otherwise recreate | ||||||
|         if (isExisting) { |         if (isExisting) { | ||||||
|             yield gitDirectoryHelper.prepareExistingDirectory(git, settings.repositoryPath, repositoryUrl, settings.clean); |             yield prepareExistingDirectory(git, settings.repositoryPath, repositoryUrl, settings.clean); | ||||||
|         } |         } | ||||||
|         if (!git) { |         if (!git) { | ||||||
|             // Downloading using REST API |             // Downloading using REST API | ||||||
|             core.info(`The repository will be downloaded using the GitHub REST API`); |             core.info(`The repository will be downloaded using the GitHub REST API`); | ||||||
|             core.info(`To create a local Git repository instead, add Git ${gitCommandManager.MinimumGitVersion} or higher to the PATH`); |             core.info(`To create a local Git repository instead, add Git ${gitCommandManager.MinimumGitVersion} or higher to the PATH`); | ||||||
|             if (settings.submodules) { |  | ||||||
|                 throw new Error(`Input 'submodules' not supported when falling back to download using the GitHub REST API. To create a local Git repository instead, add Git ${gitCommandManager.MinimumGitVersion} or higher to the PATH.`); |  | ||||||
|             } |  | ||||||
|             else if (settings.sshKey) { |  | ||||||
|                 throw new Error(`Input 'ssh-key' not supported when falling back to download using the GitHub REST API. To create a local Git repository instead, add Git ${gitCommandManager.MinimumGitVersion} or higher to the PATH.`); |  | ||||||
|             } |  | ||||||
|             yield githubApiHelper.downloadRepository(settings.authToken, settings.repositoryOwner, settings.repositoryName, settings.ref, settings.commit, settings.repositoryPath); |             yield githubApiHelper.downloadRepository(settings.authToken, settings.repositoryOwner, settings.repositoryName, settings.ref, settings.commit, settings.repositoryPath); | ||||||
|             return; |  | ||||||
|         } |         } | ||||||
|  |         else { | ||||||
|             // Save state for POST action |             // Save state for POST action | ||||||
|             stateHelper.setRepositoryPath(settings.repositoryPath); |             stateHelper.setRepositoryPath(settings.repositoryPath); | ||||||
|             // Initialize the repository |             // Initialize the repository | ||||||
|             if (!fsHelper.directoryExistsSync(path.join(settings.repositoryPath, '.git'))) { |             if (!fsHelper.directoryExistsSync(path.join(settings.repositoryPath, '.git'))) { | ||||||
|             core.startGroup('Initializing the repository'); |  | ||||||
|                 yield git.init(); |                 yield git.init(); | ||||||
|                 yield git.remoteAdd('origin', repositoryUrl); |                 yield git.remoteAdd('origin', repositoryUrl); | ||||||
|             core.endGroup(); |  | ||||||
|             } |             } | ||||||
|             // Disable automatic garbage collection |             // Disable automatic garbage collection | ||||||
|         core.startGroup('Disabling automatic garbage collection'); |  | ||||||
|             if (!(yield git.tryDisableAutomaticGarbageCollection())) { |             if (!(yield git.tryDisableAutomaticGarbageCollection())) { | ||||||
|                 core.warning(`Unable to turn off git automatic garbage collection. The git fetch operation may trigger garbage collection and cause a delay.`); |                 core.warning(`Unable to turn off git automatic garbage collection. The git fetch operation may trigger garbage collection and cause a delay.`); | ||||||
|             } |             } | ||||||
|         core.endGroup(); |             // Remove possible previous extraheader | ||||||
|         const authHelper = gitAuthHelper.createAuthHelper(git, settings); |             yield removeGitConfig(git, authConfigKey); | ||||||
|             try { |             try { | ||||||
|             // Configure auth |                 // Config extraheader | ||||||
|             core.startGroup('Setting up auth'); |                 yield configureAuthToken(git, settings.authToken); | ||||||
|             yield authHelper.configureAuth(); |  | ||||||
|             core.endGroup(); |  | ||||||
|                 // LFS install |                 // LFS install | ||||||
|                 if (settings.lfs) { |                 if (settings.lfs) { | ||||||
|                     yield git.lfsInstall(); |                     yield git.lfsInstall(); | ||||||
|                 } |                 } | ||||||
|                 // Fetch |                 // Fetch | ||||||
|             core.startGroup('Fetching the repository'); |  | ||||||
|                 const refSpec = refHelper.getRefSpec(settings.ref, settings.commit); |                 const refSpec = refHelper.getRefSpec(settings.ref, settings.commit); | ||||||
|                 yield git.fetch(settings.fetchDepth, refSpec); |                 yield git.fetch(settings.fetchDepth, refSpec); | ||||||
|             core.endGroup(); |  | ||||||
|                 // Checkout info |                 // Checkout info | ||||||
|             core.startGroup('Determining the checkout info'); |  | ||||||
|                 const checkoutInfo = yield refHelper.getCheckoutInfo(git, settings.ref, settings.commit); |                 const checkoutInfo = yield refHelper.getCheckoutInfo(git, settings.ref, settings.commit); | ||||||
|             core.endGroup(); |  | ||||||
|                 // LFS fetch |                 // LFS fetch | ||||||
|                 // Explicit lfs-fetch to avoid slow checkout (fetches one lfs object at a time). |                 // Explicit lfs-fetch to avoid slow checkout (fetches one lfs object at a time). | ||||||
|                 // Explicit lfs fetch will fetch lfs objects in parallel. |                 // Explicit lfs fetch will fetch lfs objects in parallel. | ||||||
|                 if (settings.lfs) { |                 if (settings.lfs) { | ||||||
|                 core.startGroup('Fetching LFS objects'); |  | ||||||
|                     yield git.lfsFetch(checkoutInfo.startPoint || checkoutInfo.ref); |                     yield git.lfsFetch(checkoutInfo.startPoint || checkoutInfo.ref); | ||||||
|                 core.endGroup(); |  | ||||||
|                 } |                 } | ||||||
|                 // Checkout |                 // Checkout | ||||||
|             core.startGroup('Checking out the ref'); |  | ||||||
|                 yield git.checkout(checkoutInfo.ref, checkoutInfo.startPoint); |                 yield git.checkout(checkoutInfo.ref, checkoutInfo.startPoint); | ||||||
|             core.endGroup(); |  | ||||||
|             // Submodules |  | ||||||
|             if (settings.submodules) { |  | ||||||
|                 try { |  | ||||||
|                     // Temporarily override global config |  | ||||||
|                     core.startGroup('Setting up auth for fetching submodules'); |  | ||||||
|                     yield authHelper.configureGlobalAuth(); |  | ||||||
|                     core.endGroup(); |  | ||||||
|                     // Checkout submodules |  | ||||||
|                     core.startGroup('Fetching submodules'); |  | ||||||
|                     yield git.submoduleSync(settings.nestedSubmodules); |  | ||||||
|                     yield git.submoduleUpdate(settings.fetchDepth, settings.nestedSubmodules); |  | ||||||
|                     yield git.submoduleForeach('git config --local gc.auto 0', settings.nestedSubmodules); |  | ||||||
|                     core.endGroup(); |  | ||||||
|                     // Persist credentials |  | ||||||
|                     if (settings.persistCredentials) { |  | ||||||
|                         core.startGroup('Persisting credentials for submodules'); |  | ||||||
|                         yield authHelper.configureSubmoduleAuth(); |  | ||||||
|                         core.endGroup(); |  | ||||||
|                     } |  | ||||||
|                 } |  | ||||||
|                 finally { |  | ||||||
|                     // Remove temporary global config override |  | ||||||
|                     yield authHelper.removeGlobalAuth(); |  | ||||||
|                 } |  | ||||||
|             } |  | ||||||
|                 // Dump some info about the checked out commit |                 // Dump some info about the checked out commit | ||||||
|                 yield git.log1(); |                 yield git.log1(); | ||||||
|             } |             } | ||||||
|             finally { |             finally { | ||||||
|             // Remove auth |  | ||||||
|                 if (!settings.persistCredentials) { |                 if (!settings.persistCredentials) { | ||||||
|                 core.startGroup('Removing auth'); |                     yield removeGitConfig(git, authConfigKey); | ||||||
|                 yield authHelper.removeAuth(); |                 } | ||||||
|                 core.endGroup(); |  | ||||||
|             } |             } | ||||||
|         } |         } | ||||||
|     }); |     }); | ||||||
| @@ -5970,22 +5512,22 @@ function cleanup(repositoryPath) { | |||||||
|         } |         } | ||||||
|         let git; |         let git; | ||||||
|         try { |         try { | ||||||
|             git = yield gitCommandManager.createCommandManager(repositoryPath, false); |             git = yield gitCommandManager.CreateCommandManager(repositoryPath, false); | ||||||
|         } |         } | ||||||
|         catch (_a) { |         catch (_a) { | ||||||
|             return; |             return; | ||||||
|         } |         } | ||||||
|         // Remove auth |         // Remove extraheader | ||||||
|         const authHelper = gitAuthHelper.createAuthHelper(git); |         yield removeGitConfig(git, authConfigKey); | ||||||
|         yield authHelper.removeAuth(); |  | ||||||
|     }); |     }); | ||||||
| } | } | ||||||
| exports.cleanup = cleanup; | exports.cleanup = cleanup; | ||||||
| function getGitCommandManager(settings) { | function getGitCommandManager(settings) { | ||||||
|     return __awaiter(this, void 0, void 0, function* () { |     return __awaiter(this, void 0, void 0, function* () { | ||||||
|         core.info(`Working directory is '${settings.repositoryPath}'`); |         core.info(`Working directory is '${settings.repositoryPath}'`); | ||||||
|  |         let git = null; | ||||||
|         try { |         try { | ||||||
|             return yield gitCommandManager.createCommandManager(settings.repositoryPath, settings.lfs); |             return yield gitCommandManager.CreateCommandManager(settings.repositoryPath, settings.lfs); | ||||||
|         } |         } | ||||||
|         catch (err) { |         catch (err) { | ||||||
|             // Git is required for LFS |             // Git is required for LFS | ||||||
| @@ -5993,7 +5535,108 @@ function getGitCommandManager(settings) { | |||||||
|                 throw err; |                 throw err; | ||||||
|             } |             } | ||||||
|             // Otherwise fallback to REST API |             // Otherwise fallback to REST API | ||||||
|             return undefined; |             return null; | ||||||
|  |         } | ||||||
|  |     }); | ||||||
|  | } | ||||||
|  | function prepareExistingDirectory(git, repositoryPath, repositoryUrl, clean) { | ||||||
|  |     return __awaiter(this, void 0, void 0, function* () { | ||||||
|  |         let remove = false; | ||||||
|  |         // Check whether using git or REST API | ||||||
|  |         if (!git) { | ||||||
|  |             remove = true; | ||||||
|  |         } | ||||||
|  |         // Fetch URL does not match | ||||||
|  |         else if (!fsHelper.directoryExistsSync(path.join(repositoryPath, '.git')) || | ||||||
|  |             repositoryUrl !== (yield git.tryGetFetchUrl())) { | ||||||
|  |             remove = true; | ||||||
|  |         } | ||||||
|  |         else { | ||||||
|  |             // Delete any index.lock and shallow.lock left by a previously canceled run or crashed git process | ||||||
|  |             const lockPaths = [ | ||||||
|  |                 path.join(repositoryPath, '.git', 'index.lock'), | ||||||
|  |                 path.join(repositoryPath, '.git', 'shallow.lock') | ||||||
|  |             ]; | ||||||
|  |             for (const lockPath of lockPaths) { | ||||||
|  |                 try { | ||||||
|  |                     yield io.rmRF(lockPath); | ||||||
|  |                 } | ||||||
|  |                 catch (error) { | ||||||
|  |                     core.debug(`Unable to delete '${lockPath}'. ${error.message}`); | ||||||
|  |                 } | ||||||
|  |             } | ||||||
|  |             try { | ||||||
|  |                 // Checkout detached HEAD | ||||||
|  |                 if (!(yield git.isDetached())) { | ||||||
|  |                     yield git.checkoutDetach(); | ||||||
|  |                 } | ||||||
|  |                 // Remove all refs/heads/* | ||||||
|  |                 let branches = yield git.branchList(false); | ||||||
|  |                 for (const branch of branches) { | ||||||
|  |                     yield git.branchDelete(false, branch); | ||||||
|  |                 } | ||||||
|  |                 // Remove all refs/remotes/origin/* to avoid conflicts | ||||||
|  |                 branches = yield git.branchList(true); | ||||||
|  |                 for (const branch of branches) { | ||||||
|  |                     yield git.branchDelete(true, branch); | ||||||
|  |                 } | ||||||
|  |                 // Clean | ||||||
|  |                 if (clean) { | ||||||
|  |                     if (!(yield git.tryClean())) { | ||||||
|  |                         core.debug(`The clean command failed. This might be caused by: 1) path too long, 2) permission issue, or 3) file in use. For futher investigation, manually run 'git clean -ffdx' on the directory '${repositoryPath}'.`); | ||||||
|  |                         remove = true; | ||||||
|  |                     } | ||||||
|  |                     else if (!(yield git.tryReset())) { | ||||||
|  |                         remove = true; | ||||||
|  |                     } | ||||||
|  |                     if (remove) { | ||||||
|  |                         core.warning(`Unable to clean or reset the repository. The repository will be recreated instead.`); | ||||||
|  |                     } | ||||||
|  |                 } | ||||||
|  |             } | ||||||
|  |             catch (error) { | ||||||
|  |                 core.warning(`Unable to prepare the existing repository. The repository will be recreated instead.`); | ||||||
|  |                 remove = true; | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |         if (remove) { | ||||||
|  |             // Delete the contents of the directory. Don't delete the directory itself | ||||||
|  |             // since it might be the current working directory. | ||||||
|  |             core.info(`Deleting the contents of '${repositoryPath}'`); | ||||||
|  |             for (const file of yield fs.promises.readdir(repositoryPath)) { | ||||||
|  |                 yield io.rmRF(path.join(repositoryPath, file)); | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |     }); | ||||||
|  | } | ||||||
|  | function configureAuthToken(git, authToken) { | ||||||
|  |     return __awaiter(this, void 0, void 0, function* () { | ||||||
|  |         // Configure a placeholder value. This approach avoids the credential being captured | ||||||
|  |         // by process creation audit events, which are commonly logged. For more information, | ||||||
|  |         // refer to https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/component-updates/command-line-process-auditing | ||||||
|  |         const placeholder = `AUTHORIZATION: basic ***`; | ||||||
|  |         yield git.config(authConfigKey, placeholder); | ||||||
|  |         // Determine the basic credential value | ||||||
|  |         const basicCredential = Buffer.from(`x-access-token:${authToken}`, 'utf8').toString('base64'); | ||||||
|  |         core.setSecret(basicCredential); | ||||||
|  |         // Replace the value in the config file | ||||||
|  |         const configPath = path.join(git.getWorkingDirectory(), '.git', 'config'); | ||||||
|  |         let content = (yield fs.promises.readFile(configPath)).toString(); | ||||||
|  |         const placeholderIndex = content.indexOf(placeholder); | ||||||
|  |         if (placeholderIndex < 0 || | ||||||
|  |             placeholderIndex != content.lastIndexOf(placeholder)) { | ||||||
|  |             throw new Error('Unable to replace auth placeholder in .git/config'); | ||||||
|  |         } | ||||||
|  |         content = content.replace(placeholder, `AUTHORIZATION: basic ${basicCredential}`); | ||||||
|  |         yield fs.promises.writeFile(configPath, content); | ||||||
|  |     }); | ||||||
|  | } | ||||||
|  | function removeGitConfig(git, configKey) { | ||||||
|  |     return __awaiter(this, void 0, void 0, function* () { | ||||||
|  |         if ((yield git.configExists(configKey)) && | ||||||
|  |             !(yield git.tryConfigUnset(configKey))) { | ||||||
|  |             // Load the config contents | ||||||
|  |             core.warning(`Failed to remove '${configKey}' from the git config`); | ||||||
|         } |         } | ||||||
|     }); |     }); | ||||||
| } | } | ||||||
| @@ -7231,116 +6874,6 @@ function escape(s) { | |||||||
| } | } | ||||||
| //# sourceMappingURL=command.js.map | //# sourceMappingURL=command.js.map | ||||||
|  |  | ||||||
| /***/ }), |  | ||||||
|  |  | ||||||
| /***/ 438: |  | ||||||
| /***/ (function(__unusedmodule, exports, __webpack_require__) { |  | ||||||
|  |  | ||||||
| "use strict"; |  | ||||||
|  |  | ||||||
| var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) { |  | ||||||
|     function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); } |  | ||||||
|     return new (P || (P = Promise))(function (resolve, reject) { |  | ||||||
|         function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } } |  | ||||||
|         function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } } |  | ||||||
|         function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); } |  | ||||||
|         step((generator = generator.apply(thisArg, _arguments || [])).next()); |  | ||||||
|     }); |  | ||||||
| }; |  | ||||||
| var __importStar = (this && this.__importStar) || function (mod) { |  | ||||||
|     if (mod && mod.__esModule) return mod; |  | ||||||
|     var result = {}; |  | ||||||
|     if (mod != null) for (var k in mod) if (Object.hasOwnProperty.call(mod, k)) result[k] = mod[k]; |  | ||||||
|     result["default"] = mod; |  | ||||||
|     return result; |  | ||||||
| }; |  | ||||||
| Object.defineProperty(exports, "__esModule", { value: true }); |  | ||||||
| const assert = __importStar(__webpack_require__(357)); |  | ||||||
| const core = __importStar(__webpack_require__(470)); |  | ||||||
| const fs = __importStar(__webpack_require__(747)); |  | ||||||
| const fsHelper = __importStar(__webpack_require__(618)); |  | ||||||
| const io = __importStar(__webpack_require__(1)); |  | ||||||
| const path = __importStar(__webpack_require__(622)); |  | ||||||
| function prepareExistingDirectory(git, repositoryPath, repositoryUrl, clean) { |  | ||||||
|     return __awaiter(this, void 0, void 0, function* () { |  | ||||||
|         assert.ok(repositoryPath, 'Expected repositoryPath to be defined'); |  | ||||||
|         assert.ok(repositoryUrl, 'Expected repositoryUrl to be defined'); |  | ||||||
|         // Indicates whether to delete the directory contents |  | ||||||
|         let remove = false; |  | ||||||
|         // Check whether using git or REST API |  | ||||||
|         if (!git) { |  | ||||||
|             remove = true; |  | ||||||
|         } |  | ||||||
|         // Fetch URL does not match |  | ||||||
|         else if (!fsHelper.directoryExistsSync(path.join(repositoryPath, '.git')) || |  | ||||||
|             repositoryUrl !== (yield git.tryGetFetchUrl())) { |  | ||||||
|             remove = true; |  | ||||||
|         } |  | ||||||
|         else { |  | ||||||
|             // Delete any index.lock and shallow.lock left by a previously canceled run or crashed git process |  | ||||||
|             const lockPaths = [ |  | ||||||
|                 path.join(repositoryPath, '.git', 'index.lock'), |  | ||||||
|                 path.join(repositoryPath, '.git', 'shallow.lock') |  | ||||||
|             ]; |  | ||||||
|             for (const lockPath of lockPaths) { |  | ||||||
|                 try { |  | ||||||
|                     yield io.rmRF(lockPath); |  | ||||||
|                 } |  | ||||||
|                 catch (error) { |  | ||||||
|                     core.debug(`Unable to delete '${lockPath}'. ${error.message}`); |  | ||||||
|                 } |  | ||||||
|             } |  | ||||||
|             try { |  | ||||||
|                 core.startGroup('Removing previously created refs, to avoid conflicts'); |  | ||||||
|                 // Checkout detached HEAD |  | ||||||
|                 if (!(yield git.isDetached())) { |  | ||||||
|                     yield git.checkoutDetach(); |  | ||||||
|                 } |  | ||||||
|                 // Remove all refs/heads/* |  | ||||||
|                 let branches = yield git.branchList(false); |  | ||||||
|                 for (const branch of branches) { |  | ||||||
|                     yield git.branchDelete(false, branch); |  | ||||||
|                 } |  | ||||||
|                 // Remove all refs/remotes/origin/* to avoid conflicts |  | ||||||
|                 branches = yield git.branchList(true); |  | ||||||
|                 for (const branch of branches) { |  | ||||||
|                     yield git.branchDelete(true, branch); |  | ||||||
|                 } |  | ||||||
|                 core.endGroup(); |  | ||||||
|                 // Clean |  | ||||||
|                 if (clean) { |  | ||||||
|                     core.startGroup('Cleaning the repository'); |  | ||||||
|                     if (!(yield git.tryClean())) { |  | ||||||
|                         core.debug(`The clean command failed. This might be caused by: 1) path too long, 2) permission issue, or 3) file in use. For futher investigation, manually run 'git clean -ffdx' on the directory '${repositoryPath}'.`); |  | ||||||
|                         remove = true; |  | ||||||
|                     } |  | ||||||
|                     else if (!(yield git.tryReset())) { |  | ||||||
|                         remove = true; |  | ||||||
|                     } |  | ||||||
|                     core.endGroup(); |  | ||||||
|                     if (remove) { |  | ||||||
|                         core.warning(`Unable to clean or reset the repository. The repository will be recreated instead.`); |  | ||||||
|                     } |  | ||||||
|                 } |  | ||||||
|             } |  | ||||||
|             catch (error) { |  | ||||||
|                 core.warning(`Unable to prepare the existing repository. The repository will be recreated instead.`); |  | ||||||
|                 remove = true; |  | ||||||
|             } |  | ||||||
|         } |  | ||||||
|         if (remove) { |  | ||||||
|             // Delete the contents of the directory. Don't delete the directory itself |  | ||||||
|             // since it might be the current working directory. |  | ||||||
|             core.info(`Deleting the contents of '${repositoryPath}'`); |  | ||||||
|             for (const file of yield fs.promises.readdir(repositoryPath)) { |  | ||||||
|                 yield io.rmRF(path.join(repositoryPath, file)); |  | ||||||
|             } |  | ||||||
|         } |  | ||||||
|     }); |  | ||||||
| } |  | ||||||
| exports.prepareExistingDirectory = prepareExistingDirectory; |  | ||||||
|  |  | ||||||
|  |  | ||||||
| /***/ }), | /***/ }), | ||||||
|  |  | ||||||
| /***/ 453: | /***/ 453: | ||||||
| @@ -9231,7 +8764,6 @@ const io = __importStar(__webpack_require__(1)); | |||||||
| const path = __importStar(__webpack_require__(622)); | const path = __importStar(__webpack_require__(622)); | ||||||
| const retryHelper = __importStar(__webpack_require__(587)); | const retryHelper = __importStar(__webpack_require__(587)); | ||||||
| const toolCache = __importStar(__webpack_require__(533)); | const toolCache = __importStar(__webpack_require__(533)); | ||||||
| const urlHelper = __importStar(__webpack_require__(81)); |  | ||||||
| const v4_1 = __importDefault(__webpack_require__(826)); | const v4_1 = __importDefault(__webpack_require__(826)); | ||||||
| const IS_WINDOWS = process.platform === 'win32'; | const IS_WINDOWS = process.platform === 'win32'; | ||||||
| function downloadRepository(authToken, owner, repo, ref, commit, repositoryPath) { | function downloadRepository(authToken, owner, repo, ref, commit, repositoryPath) { | ||||||
| @@ -9282,7 +8814,7 @@ function downloadRepository(authToken, owner, repo, ref, commit, repositoryPath) | |||||||
| exports.downloadRepository = downloadRepository; | exports.downloadRepository = downloadRepository; | ||||||
| function downloadArchive(authToken, owner, repo, ref, commit) { | function downloadArchive(authToken, owner, repo, ref, commit) { | ||||||
|     return __awaiter(this, void 0, void 0, function* () { |     return __awaiter(this, void 0, void 0, function* () { | ||||||
|         const octokit = new github.GitHub(authToken, { baseUrl: urlHelper.getApiUrl() }); |         const octokit = new github.GitHub(authToken); | ||||||
|         const params = { |         const params = { | ||||||
|             owner: owner, |             owner: owner, | ||||||
|             repo: repo, |             repo: repo, | ||||||
| @@ -9800,22 +9332,6 @@ module.exports.Singular = Hook.Singular | |||||||
| module.exports.Collection = Hook.Collection | module.exports.Collection = Hook.Collection | ||||||
|  |  | ||||||
|  |  | ||||||
| /***/ }), |  | ||||||
|  |  | ||||||
| /***/ 528: |  | ||||||
| /***/ (function(__unusedmodule, exports) { |  | ||||||
|  |  | ||||||
| "use strict"; |  | ||||||
|  |  | ||||||
| Object.defineProperty(exports, "__esModule", { value: true }); |  | ||||||
| function escape(value) { |  | ||||||
|     return value.replace(/[^a-zA-Z0-9_]/g, x => { |  | ||||||
|         return `\\${x}`; |  | ||||||
|     }); |  | ||||||
| } |  | ||||||
| exports.escape = escape; |  | ||||||
|  |  | ||||||
|  |  | ||||||
| /***/ }), | /***/ }), | ||||||
|  |  | ||||||
| /***/ 529: | /***/ 529: | ||||||
| @@ -14119,6 +13635,10 @@ function getInputs() { | |||||||
|     // Clean |     // Clean | ||||||
|     result.clean = (core.getInput('clean') || 'true').toUpperCase() === 'TRUE'; |     result.clean = (core.getInput('clean') || 'true').toUpperCase() === 'TRUE'; | ||||||
|     core.debug(`clean = ${result.clean}`); |     core.debug(`clean = ${result.clean}`); | ||||||
|  |     // Submodules | ||||||
|  |     if (core.getInput('submodules')) { | ||||||
|  |         throw new Error("The input 'submodules' is not supported in actions/checkout@v2"); | ||||||
|  |     } | ||||||
|     // Fetch depth |     // Fetch depth | ||||||
|     result.fetchDepth = Math.floor(Number(core.getInput('fetch-depth') || '1')); |     result.fetchDepth = Math.floor(Number(core.getInput('fetch-depth') || '1')); | ||||||
|     if (isNaN(result.fetchDepth) || result.fetchDepth < 0) { |     if (isNaN(result.fetchDepth) || result.fetchDepth < 0) { | ||||||
| @@ -14128,26 +13648,8 @@ function getInputs() { | |||||||
|     // LFS |     // LFS | ||||||
|     result.lfs = (core.getInput('lfs') || 'false').toUpperCase() === 'TRUE'; |     result.lfs = (core.getInput('lfs') || 'false').toUpperCase() === 'TRUE'; | ||||||
|     core.debug(`lfs = ${result.lfs}`); |     core.debug(`lfs = ${result.lfs}`); | ||||||
|     // Submodules |  | ||||||
|     result.submodules = false; |  | ||||||
|     result.nestedSubmodules = false; |  | ||||||
|     const submodulesString = (core.getInput('submodules') || '').toUpperCase(); |  | ||||||
|     if (submodulesString == 'RECURSIVE') { |  | ||||||
|         result.submodules = true; |  | ||||||
|         result.nestedSubmodules = true; |  | ||||||
|     } |  | ||||||
|     else if (submodulesString == 'TRUE') { |  | ||||||
|         result.submodules = true; |  | ||||||
|     } |  | ||||||
|     core.debug(`submodules = ${result.submodules}`); |  | ||||||
|     core.debug(`recursive submodules = ${result.nestedSubmodules}`); |  | ||||||
|     // Auth token |     // Auth token | ||||||
|     result.authToken = core.getInput('token'); |     result.authToken = core.getInput('token'); | ||||||
|     // SSH |  | ||||||
|     result.sshKey = core.getInput('ssh-key'); |  | ||||||
|     result.sshKnownHosts = core.getInput('ssh-known-hosts'); |  | ||||||
|     result.sshStrict = |  | ||||||
|         (core.getInput('ssh-strict') || 'true').toUpperCase() === 'TRUE'; |  | ||||||
|     // Persist credentials |     // Persist credentials | ||||||
|     result.persistCredentials = |     result.persistCredentials = | ||||||
|         (core.getInput('persist-credentials') || 'false').toUpperCase() === 'TRUE'; |         (core.getInput('persist-credentials') || 'false').toUpperCase() === 'TRUE'; | ||||||
|   | |||||||
| @@ -4,11 +4,14 @@ | |||||||
|   "description": "checkout action", |   "description": "checkout action", | ||||||
|   "main": "lib/main.js", |   "main": "lib/main.js", | ||||||
|   "scripts": { |   "scripts": { | ||||||
|     "build": "tsc && ncc build && node lib/misc/generate-docs.js", |     "build": "tsc", | ||||||
|     "format": "prettier --write **/*.ts", |     "format": "prettier --write **/*.ts", | ||||||
|     "format-check": "prettier --check **/*.ts", |     "format-check": "prettier --check **/*.ts", | ||||||
|     "lint": "eslint src/**/*.ts", |     "lint": "eslint src/**/*.ts", | ||||||
|     "test": "jest" |     "pack": "ncc build", | ||||||
|  |     "gendocs": "node lib/misc/generate-docs.js", | ||||||
|  |     "test": "jest", | ||||||
|  |     "all": "npm run build && npm run format && npm run lint && npm run pack && npm run gendocs && npm test" | ||||||
|   }, |   }, | ||||||
|   "repository": { |   "repository": { | ||||||
|     "type": "git", |     "type": "git", | ||||||
|   | |||||||
| @@ -1,350 +0,0 @@ | |||||||
| import * as assert from 'assert' |  | ||||||
| import * as core from '@actions/core' |  | ||||||
| import * as exec from '@actions/exec' |  | ||||||
| import * as fs from 'fs' |  | ||||||
| import * as io from '@actions/io' |  | ||||||
| import * as os from 'os' |  | ||||||
| import * as path from 'path' |  | ||||||
| import * as regexpHelper from './regexp-helper' |  | ||||||
| import * as stateHelper from './state-helper' |  | ||||||
| import * as urlHelper from './url-helper' |  | ||||||
| import {default as uuid} from 'uuid/v4' |  | ||||||
| import {IGitCommandManager} from './git-command-manager' |  | ||||||
| import {IGitSourceSettings} from './git-source-settings' |  | ||||||
|  |  | ||||||
| const IS_WINDOWS = process.platform === 'win32' |  | ||||||
| const SSH_COMMAND_KEY = 'core.sshCommand' |  | ||||||
|  |  | ||||||
| export interface IGitAuthHelper { |  | ||||||
|   configureAuth(): Promise<void> |  | ||||||
|   configureGlobalAuth(): Promise<void> |  | ||||||
|   configureSubmoduleAuth(): Promise<void> |  | ||||||
|   removeAuth(): Promise<void> |  | ||||||
|   removeGlobalAuth(): Promise<void> |  | ||||||
| } |  | ||||||
|  |  | ||||||
| export function createAuthHelper( |  | ||||||
|   git: IGitCommandManager, |  | ||||||
|   settings?: IGitSourceSettings |  | ||||||
| ): IGitAuthHelper { |  | ||||||
|   return new GitAuthHelper(git, settings) |  | ||||||
| } |  | ||||||
|  |  | ||||||
| class GitAuthHelper { |  | ||||||
|   private readonly git: IGitCommandManager |  | ||||||
|   private readonly settings: IGitSourceSettings |  | ||||||
|   private readonly tokenConfigKey: string |  | ||||||
|   private readonly tokenConfigValue: string |  | ||||||
|   private readonly tokenPlaceholderConfigValue: string |  | ||||||
|   private readonly insteadOfKey: string |  | ||||||
|   private readonly insteadOfValue: string |  | ||||||
|   private sshCommand = '' |  | ||||||
|   private sshKeyPath = '' |  | ||||||
|   private sshKnownHostsPath = '' |  | ||||||
|   private temporaryHomePath = '' |  | ||||||
|  |  | ||||||
|   constructor( |  | ||||||
|     gitCommandManager: IGitCommandManager, |  | ||||||
|     gitSourceSettings?: IGitSourceSettings |  | ||||||
|   ) { |  | ||||||
|     this.git = gitCommandManager |  | ||||||
|     this.settings = gitSourceSettings || (({} as unknown) as IGitSourceSettings) |  | ||||||
|  |  | ||||||
|     // Token auth header |  | ||||||
|     const serverUrl = urlHelper.getServerUrl() |  | ||||||
|     this.tokenConfigKey = `http.${serverUrl.origin}/.extraheader` // "origin" is SCHEME://HOSTNAME[:PORT] |  | ||||||
|     const basicCredential = Buffer.from( |  | ||||||
|       `x-access-token:${this.settings.authToken}`, |  | ||||||
|       'utf8' |  | ||||||
|     ).toString('base64') |  | ||||||
|     core.setSecret(basicCredential) |  | ||||||
|     this.tokenPlaceholderConfigValue = `AUTHORIZATION: basic ***` |  | ||||||
|     this.tokenConfigValue = `AUTHORIZATION: basic ${basicCredential}` |  | ||||||
|  |  | ||||||
|     // Instead of SSH URL |  | ||||||
|     this.insteadOfKey = `url.${serverUrl.origin}/.insteadOf` // "origin" is SCHEME://HOSTNAME[:PORT] |  | ||||||
|     this.insteadOfValue = `git@${serverUrl.hostname}:` |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   async configureAuth(): Promise<void> { |  | ||||||
|     // Remove possible previous values |  | ||||||
|     await this.removeAuth() |  | ||||||
|  |  | ||||||
|     // Configure new values |  | ||||||
|     await this.configureSsh() |  | ||||||
|     await this.configureToken() |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   async configureGlobalAuth(): Promise<void> { |  | ||||||
|     // Create a temp home directory |  | ||||||
|     const runnerTemp = process.env['RUNNER_TEMP'] || '' |  | ||||||
|     assert.ok(runnerTemp, 'RUNNER_TEMP is not defined') |  | ||||||
|     const uniqueId = uuid() |  | ||||||
|     this.temporaryHomePath = path.join(runnerTemp, uniqueId) |  | ||||||
|     await fs.promises.mkdir(this.temporaryHomePath, {recursive: true}) |  | ||||||
|  |  | ||||||
|     // Copy the global git config |  | ||||||
|     const gitConfigPath = path.join( |  | ||||||
|       process.env['HOME'] || os.homedir(), |  | ||||||
|       '.gitconfig' |  | ||||||
|     ) |  | ||||||
|     const newGitConfigPath = path.join(this.temporaryHomePath, '.gitconfig') |  | ||||||
|     let configExists = false |  | ||||||
|     try { |  | ||||||
|       await fs.promises.stat(gitConfigPath) |  | ||||||
|       configExists = true |  | ||||||
|     } catch (err) { |  | ||||||
|       if (err.code !== 'ENOENT') { |  | ||||||
|         throw err |  | ||||||
|       } |  | ||||||
|     } |  | ||||||
|     if (configExists) { |  | ||||||
|       core.info(`Copying '${gitConfigPath}' to '${newGitConfigPath}'`) |  | ||||||
|       await io.cp(gitConfigPath, newGitConfigPath) |  | ||||||
|     } else { |  | ||||||
|       await fs.promises.writeFile(newGitConfigPath, '') |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     try { |  | ||||||
|       // Override HOME |  | ||||||
|       core.info( |  | ||||||
|         `Temporarily overriding HOME='${this.temporaryHomePath}' before making global git config changes` |  | ||||||
|       ) |  | ||||||
|       this.git.setEnvironmentVariable('HOME', this.temporaryHomePath) |  | ||||||
|  |  | ||||||
|       // Configure the token |  | ||||||
|       await this.configureToken(newGitConfigPath, true) |  | ||||||
|  |  | ||||||
|       // Configure HTTPS instead of SSH |  | ||||||
|       await this.git.tryConfigUnset(this.insteadOfKey, true) |  | ||||||
|       if (!this.settings.sshKey) { |  | ||||||
|         await this.git.config(this.insteadOfKey, this.insteadOfValue, true) |  | ||||||
|       } |  | ||||||
|     } catch (err) { |  | ||||||
|       // Unset in case somehow written to the real global config |  | ||||||
|       core.info( |  | ||||||
|         'Encountered an error when attempting to configure token. Attempting unconfigure.' |  | ||||||
|       ) |  | ||||||
|       await this.git.tryConfigUnset(this.tokenConfigKey, true) |  | ||||||
|       throw err |  | ||||||
|     } |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   async configureSubmoduleAuth(): Promise<void> { |  | ||||||
|     // Remove possible previous HTTPS instead of SSH |  | ||||||
|     await this.removeGitConfig(this.insteadOfKey, true) |  | ||||||
|  |  | ||||||
|     if (this.settings.persistCredentials) { |  | ||||||
|       // Configure a placeholder value. This approach avoids the credential being captured |  | ||||||
|       // by process creation audit events, which are commonly logged. For more information, |  | ||||||
|       // refer to https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/component-updates/command-line-process-auditing |  | ||||||
|       const output = await this.git.submoduleForeach( |  | ||||||
|         `git config --local '${this.tokenConfigKey}' '${this.tokenPlaceholderConfigValue}' && git config --local --show-origin --name-only --get-regexp remote.origin.url`, |  | ||||||
|         this.settings.nestedSubmodules |  | ||||||
|       ) |  | ||||||
|  |  | ||||||
|       // Replace the placeholder |  | ||||||
|       const configPaths: string[] = |  | ||||||
|         output.match(/(?<=(^|\n)file:)[^\t]+(?=\tremote\.origin\.url)/g) || [] |  | ||||||
|       for (const configPath of configPaths) { |  | ||||||
|         core.debug(`Replacing token placeholder in '${configPath}'`) |  | ||||||
|         this.replaceTokenPlaceholder(configPath) |  | ||||||
|       } |  | ||||||
|  |  | ||||||
|       if (this.settings.sshKey) { |  | ||||||
|         // Configure core.sshCommand |  | ||||||
|         await this.git.submoduleForeach( |  | ||||||
|           `git config --local '${SSH_COMMAND_KEY}' '${this.sshCommand}'`, |  | ||||||
|           this.settings.nestedSubmodules |  | ||||||
|         ) |  | ||||||
|       } else { |  | ||||||
|         // Configure HTTPS instead of SSH |  | ||||||
|         await this.git.submoduleForeach( |  | ||||||
|           `git config --local '${this.insteadOfKey}' '${this.insteadOfValue}'`, |  | ||||||
|           this.settings.nestedSubmodules |  | ||||||
|         ) |  | ||||||
|       } |  | ||||||
|     } |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   async removeAuth(): Promise<void> { |  | ||||||
|     await this.removeSsh() |  | ||||||
|     await this.removeToken() |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   async removeGlobalAuth(): Promise<void> { |  | ||||||
|     core.debug(`Unsetting HOME override`) |  | ||||||
|     this.git.removeEnvironmentVariable('HOME') |  | ||||||
|     await io.rmRF(this.temporaryHomePath) |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   private async configureSsh(): Promise<void> { |  | ||||||
|     if (!this.settings.sshKey) { |  | ||||||
|       return |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // Write key |  | ||||||
|     const runnerTemp = process.env['RUNNER_TEMP'] || '' |  | ||||||
|     assert.ok(runnerTemp, 'RUNNER_TEMP is not defined') |  | ||||||
|     const uniqueId = uuid() |  | ||||||
|     this.sshKeyPath = path.join(runnerTemp, uniqueId) |  | ||||||
|     stateHelper.setSshKeyPath(this.sshKeyPath) |  | ||||||
|     await fs.promises.mkdir(runnerTemp, {recursive: true}) |  | ||||||
|     await fs.promises.writeFile( |  | ||||||
|       this.sshKeyPath, |  | ||||||
|       this.settings.sshKey.trim() + '\n', |  | ||||||
|       {mode: 0o600} |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Remove inherited permissions on Windows |  | ||||||
|     if (IS_WINDOWS) { |  | ||||||
|       const icacls = await io.which('icacls.exe') |  | ||||||
|       await exec.exec( |  | ||||||
|         `"${icacls}" "${this.sshKeyPath}" /grant:r "${process.env['USERDOMAIN']}\\${process.env['USERNAME']}:F"` |  | ||||||
|       ) |  | ||||||
|       await exec.exec(`"${icacls}" "${this.sshKeyPath}" /inheritance:r`) |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // Write known hosts |  | ||||||
|     const userKnownHostsPath = path.join(os.homedir(), '.ssh', 'known_hosts') |  | ||||||
|     let userKnownHosts = '' |  | ||||||
|     try { |  | ||||||
|       userKnownHosts = ( |  | ||||||
|         await fs.promises.readFile(userKnownHostsPath) |  | ||||||
|       ).toString() |  | ||||||
|     } catch (err) { |  | ||||||
|       if (err.code !== 'ENOENT') { |  | ||||||
|         throw err |  | ||||||
|       } |  | ||||||
|     } |  | ||||||
|     let knownHosts = '' |  | ||||||
|     if (userKnownHosts) { |  | ||||||
|       knownHosts += `# Begin from ${userKnownHostsPath}\n${userKnownHosts}\n# End from ${userKnownHostsPath}\n` |  | ||||||
|     } |  | ||||||
|     if (this.settings.sshKnownHosts) { |  | ||||||
|       knownHosts += `# Begin from input known hosts\n${this.settings.sshKnownHosts}\n# end from input known hosts\n` |  | ||||||
|     } |  | ||||||
|     knownHosts += `# Begin implicitly added github.com\ngithub.com ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAq2A7hRGmdnm9tUDbO9IDSwBK6TbQa+PXYPCPy6rbTrTtw7PHkccKrpp0yVhp5HdEIcKr6pLlVDBfOLX9QUsyCOV0wzfjIJNlGEYsdlLJizHhbn2mUjvSAHQqZETYP81eFzLQNnPHt4EVVUh7VfDESU84KezmD5QlWpXLmvU31/yMf+Se8xhHTvKSCZIFImWwoG6mbUoWf9nzpIoaSjB+weqqUUmpaaasXVal72J+UX2B+2RPW3RcT0eOzQgqlJL3RKrTJvdsjE3JEAvGq3lGHSZXy28G3skua2SmVi/w4yCE6gbODqnTWlg7+wC604ydGXA8VJiS5ap43JXiUFFAaQ==\n# End implicitly added github.com\n` |  | ||||||
|     this.sshKnownHostsPath = path.join(runnerTemp, `${uniqueId}_known_hosts`) |  | ||||||
|     stateHelper.setSshKnownHostsPath(this.sshKnownHostsPath) |  | ||||||
|     await fs.promises.writeFile(this.sshKnownHostsPath, knownHosts) |  | ||||||
|  |  | ||||||
|     // Configure GIT_SSH_COMMAND |  | ||||||
|     const sshPath = await io.which('ssh', true) |  | ||||||
|     this.sshCommand = `"${sshPath}" -i "$RUNNER_TEMP/${path.basename( |  | ||||||
|       this.sshKeyPath |  | ||||||
|     )}"` |  | ||||||
|     if (this.settings.sshStrict) { |  | ||||||
|       this.sshCommand += ' -o StrictHostKeyChecking=yes -o CheckHostIP=no' |  | ||||||
|     } |  | ||||||
|     this.sshCommand += ` -o "UserKnownHostsFile=$RUNNER_TEMP/${path.basename( |  | ||||||
|       this.sshKnownHostsPath |  | ||||||
|     )}"` |  | ||||||
|     core.info(`Temporarily overriding GIT_SSH_COMMAND=${this.sshCommand}`) |  | ||||||
|     this.git.setEnvironmentVariable('GIT_SSH_COMMAND', this.sshCommand) |  | ||||||
|  |  | ||||||
|     // Configure core.sshCommand |  | ||||||
|     if (this.settings.persistCredentials) { |  | ||||||
|       await this.git.config(SSH_COMMAND_KEY, this.sshCommand) |  | ||||||
|     } |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   private async configureToken( |  | ||||||
|     configPath?: string, |  | ||||||
|     globalConfig?: boolean |  | ||||||
|   ): Promise<void> { |  | ||||||
|     // Validate args |  | ||||||
|     assert.ok( |  | ||||||
|       (configPath && globalConfig) || (!configPath && !globalConfig), |  | ||||||
|       'Unexpected configureToken parameter combinations' |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Default config path |  | ||||||
|     if (!configPath && !globalConfig) { |  | ||||||
|       configPath = path.join(this.git.getWorkingDirectory(), '.git', 'config') |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // Configure a placeholder value. This approach avoids the credential being captured |  | ||||||
|     // by process creation audit events, which are commonly logged. For more information, |  | ||||||
|     // refer to https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/component-updates/command-line-process-auditing |  | ||||||
|     await this.git.config( |  | ||||||
|       this.tokenConfigKey, |  | ||||||
|       this.tokenPlaceholderConfigValue, |  | ||||||
|       globalConfig |  | ||||||
|     ) |  | ||||||
|  |  | ||||||
|     // Replace the placeholder |  | ||||||
|     await this.replaceTokenPlaceholder(configPath || '') |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   private async replaceTokenPlaceholder(configPath: string): Promise<void> { |  | ||||||
|     assert.ok(configPath, 'configPath is not defined') |  | ||||||
|     let content = (await fs.promises.readFile(configPath)).toString() |  | ||||||
|     const placeholderIndex = content.indexOf(this.tokenPlaceholderConfigValue) |  | ||||||
|     if ( |  | ||||||
|       placeholderIndex < 0 || |  | ||||||
|       placeholderIndex != content.lastIndexOf(this.tokenPlaceholderConfigValue) |  | ||||||
|     ) { |  | ||||||
|       throw new Error(`Unable to replace auth placeholder in ${configPath}`) |  | ||||||
|     } |  | ||||||
|     assert.ok(this.tokenConfigValue, 'tokenConfigValue is not defined') |  | ||||||
|     content = content.replace( |  | ||||||
|       this.tokenPlaceholderConfigValue, |  | ||||||
|       this.tokenConfigValue |  | ||||||
|     ) |  | ||||||
|     await fs.promises.writeFile(configPath, content) |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   private async removeSsh(): Promise<void> { |  | ||||||
|     // SSH key |  | ||||||
|     const keyPath = this.sshKeyPath || stateHelper.SshKeyPath |  | ||||||
|     if (keyPath) { |  | ||||||
|       try { |  | ||||||
|         await io.rmRF(keyPath) |  | ||||||
|       } catch (err) { |  | ||||||
|         core.debug(err.message) |  | ||||||
|         core.warning(`Failed to remove SSH key '${keyPath}'`) |  | ||||||
|       } |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // SSH known hosts |  | ||||||
|     const knownHostsPath = |  | ||||||
|       this.sshKnownHostsPath || stateHelper.SshKnownHostsPath |  | ||||||
|     if (knownHostsPath) { |  | ||||||
|       try { |  | ||||||
|         await io.rmRF(knownHostsPath) |  | ||||||
|       } catch { |  | ||||||
|         // Intentionally empty |  | ||||||
|       } |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // SSH command |  | ||||||
|     await this.removeGitConfig(SSH_COMMAND_KEY) |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   private async removeToken(): Promise<void> { |  | ||||||
|     // HTTP extra header |  | ||||||
|     await this.removeGitConfig(this.tokenConfigKey) |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   private async removeGitConfig( |  | ||||||
|     configKey: string, |  | ||||||
|     submoduleOnly: boolean = false |  | ||||||
|   ): Promise<void> { |  | ||||||
|     if (!submoduleOnly) { |  | ||||||
|       if ( |  | ||||||
|         (await this.git.configExists(configKey)) && |  | ||||||
|         !(await this.git.tryConfigUnset(configKey)) |  | ||||||
|       ) { |  | ||||||
|         // Load the config contents |  | ||||||
|         core.warning(`Failed to remove '${configKey}' from the git config`) |  | ||||||
|       } |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     const pattern = regexpHelper.escape(configKey) |  | ||||||
|     await this.git.submoduleForeach( |  | ||||||
|       `git config --local --name-only --get-regexp '${pattern}' && git config --local --unset-all '${configKey}' || :`, |  | ||||||
|       true |  | ||||||
|     ) |  | ||||||
|   } |  | ||||||
| } |  | ||||||
| @@ -3,7 +3,6 @@ import * as exec from '@actions/exec' | |||||||
| import * as fshelper from './fs-helper' | import * as fshelper from './fs-helper' | ||||||
| import * as io from '@actions/io' | import * as io from '@actions/io' | ||||||
| import * as path from 'path' | import * as path from 'path' | ||||||
| import * as regexpHelper from './regexp-helper' |  | ||||||
| import * as retryHelper from './retry-helper' | import * as retryHelper from './retry-helper' | ||||||
| import {GitVersion} from './git-version' | import {GitVersion} from './git-version' | ||||||
|  |  | ||||||
| @@ -17,12 +16,8 @@ export interface IGitCommandManager { | |||||||
|   branchList(remote: boolean): Promise<string[]> |   branchList(remote: boolean): Promise<string[]> | ||||||
|   checkout(ref: string, startPoint: string): Promise<void> |   checkout(ref: string, startPoint: string): Promise<void> | ||||||
|   checkoutDetach(): Promise<void> |   checkoutDetach(): Promise<void> | ||||||
|   config( |   config(configKey: string, configValue: string): Promise<void> | ||||||
|     configKey: string, |   configExists(configKey: string): Promise<boolean> | ||||||
|     configValue: string, |  | ||||||
|     globalConfig?: boolean |  | ||||||
|   ): Promise<void> |  | ||||||
|   configExists(configKey: string, globalConfig?: boolean): Promise<boolean> |  | ||||||
|   fetch(fetchDepth: number, refSpec: string[]): Promise<void> |   fetch(fetchDepth: number, refSpec: string[]): Promise<void> | ||||||
|   getWorkingDirectory(): string |   getWorkingDirectory(): string | ||||||
|   init(): Promise<void> |   init(): Promise<void> | ||||||
| @@ -31,20 +26,15 @@ export interface IGitCommandManager { | |||||||
|   lfsInstall(): Promise<void> |   lfsInstall(): Promise<void> | ||||||
|   log1(): Promise<void> |   log1(): Promise<void> | ||||||
|   remoteAdd(remoteName: string, remoteUrl: string): Promise<void> |   remoteAdd(remoteName: string, remoteUrl: string): Promise<void> | ||||||
|   removeEnvironmentVariable(name: string): void |  | ||||||
|   setEnvironmentVariable(name: string, value: string): void |  | ||||||
|   submoduleForeach(command: string, recursive: boolean): Promise<string> |  | ||||||
|   submoduleSync(recursive: boolean): Promise<void> |  | ||||||
|   submoduleUpdate(fetchDepth: number, recursive: boolean): Promise<void> |  | ||||||
|   tagExists(pattern: string): Promise<boolean> |   tagExists(pattern: string): Promise<boolean> | ||||||
|   tryClean(): Promise<boolean> |   tryClean(): Promise<boolean> | ||||||
|   tryConfigUnset(configKey: string, globalConfig?: boolean): Promise<boolean> |   tryConfigUnset(configKey: string): Promise<boolean> | ||||||
|   tryDisableAutomaticGarbageCollection(): Promise<boolean> |   tryDisableAutomaticGarbageCollection(): Promise<boolean> | ||||||
|   tryGetFetchUrl(): Promise<string> |   tryGetFetchUrl(): Promise<string> | ||||||
|   tryReset(): Promise<boolean> |   tryReset(): Promise<boolean> | ||||||
| } | } | ||||||
|  |  | ||||||
| export async function createCommandManager( | export async function CreateCommandManager( | ||||||
|   workingDirectory: string, |   workingDirectory: string, | ||||||
|   lfs: boolean |   lfs: boolean | ||||||
| ): Promise<IGitCommandManager> { | ): Promise<IGitCommandManager> { | ||||||
| @@ -133,32 +123,16 @@ class GitCommandManager { | |||||||
|     await this.execGit(args) |     await this.execGit(args) | ||||||
|   } |   } | ||||||
|  |  | ||||||
|   async config( |   async config(configKey: string, configValue: string): Promise<void> { | ||||||
|     configKey: string, |     await this.execGit(['config', '--local', configKey, configValue]) | ||||||
|     configValue: string, |  | ||||||
|     globalConfig?: boolean |  | ||||||
|   ): Promise<void> { |  | ||||||
|     await this.execGit([ |  | ||||||
|       'config', |  | ||||||
|       globalConfig ? '--global' : '--local', |  | ||||||
|       configKey, |  | ||||||
|       configValue |  | ||||||
|     ]) |  | ||||||
|   } |   } | ||||||
|  |  | ||||||
|   async configExists( |   async configExists(configKey: string): Promise<boolean> { | ||||||
|     configKey: string, |     const pattern = configKey.replace(/[^a-zA-Z0-9_]/g, x => { | ||||||
|     globalConfig?: boolean |       return `\\${x}` | ||||||
|   ): Promise<boolean> { |     }) | ||||||
|     const pattern = regexpHelper.escape(configKey) |  | ||||||
|     const output = await this.execGit( |     const output = await this.execGit( | ||||||
|       [ |       ['config', '--local', '--name-only', '--get-regexp', pattern], | ||||||
|         'config', |  | ||||||
|         globalConfig ? '--global' : '--local', |  | ||||||
|         '--name-only', |  | ||||||
|         '--get-regexp', |  | ||||||
|         pattern |  | ||||||
|       ], |  | ||||||
|       true |       true | ||||||
|     ) |     ) | ||||||
|     return output.exitCode === 0 |     return output.exitCode === 0 | ||||||
| @@ -233,48 +207,6 @@ class GitCommandManager { | |||||||
|     await this.execGit(['remote', 'add', remoteName, remoteUrl]) |     await this.execGit(['remote', 'add', remoteName, remoteUrl]) | ||||||
|   } |   } | ||||||
|  |  | ||||||
|   removeEnvironmentVariable(name: string): void { |  | ||||||
|     delete this.gitEnv[name] |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   setEnvironmentVariable(name: string, value: string): void { |  | ||||||
|     this.gitEnv[name] = value |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   async submoduleForeach(command: string, recursive: boolean): Promise<string> { |  | ||||||
|     const args = ['submodule', 'foreach'] |  | ||||||
|     if (recursive) { |  | ||||||
|       args.push('--recursive') |  | ||||||
|     } |  | ||||||
|     args.push(command) |  | ||||||
|  |  | ||||||
|     const output = await this.execGit(args) |  | ||||||
|     return output.stdout |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   async submoduleSync(recursive: boolean): Promise<void> { |  | ||||||
|     const args = ['submodule', 'sync'] |  | ||||||
|     if (recursive) { |  | ||||||
|       args.push('--recursive') |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     await this.execGit(args) |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   async submoduleUpdate(fetchDepth: number, recursive: boolean): Promise<void> { |  | ||||||
|     const args = ['-c', 'protocol.version=2'] |  | ||||||
|     args.push('submodule', 'update', '--init', '--force') |  | ||||||
|     if (fetchDepth > 0) { |  | ||||||
|       args.push(`--depth=${fetchDepth}`) |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     if (recursive) { |  | ||||||
|       args.push('--recursive') |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     await this.execGit(args) |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   async tagExists(pattern: string): Promise<boolean> { |   async tagExists(pattern: string): Promise<boolean> { | ||||||
|     const output = await this.execGit(['tag', '--list', pattern]) |     const output = await this.execGit(['tag', '--list', pattern]) | ||||||
|     return !!output.stdout.trim() |     return !!output.stdout.trim() | ||||||
| @@ -285,17 +217,9 @@ class GitCommandManager { | |||||||
|     return output.exitCode === 0 |     return output.exitCode === 0 | ||||||
|   } |   } | ||||||
|  |  | ||||||
|   async tryConfigUnset( |   async tryConfigUnset(configKey: string): Promise<boolean> { | ||||||
|     configKey: string, |  | ||||||
|     globalConfig?: boolean |  | ||||||
|   ): Promise<boolean> { |  | ||||||
|     const output = await this.execGit( |     const output = await this.execGit( | ||||||
|       [ |       ['config', '--local', '--unset-all', configKey], | ||||||
|         'config', |  | ||||||
|         globalConfig ? '--global' : '--local', |  | ||||||
|         '--unset-all', |  | ||||||
|         configKey |  | ||||||
|       ], |  | ||||||
|       true |       true | ||||||
|     ) |     ) | ||||||
|     return output.exitCode === 0 |     return output.exitCode === 0 | ||||||
|   | |||||||
| @@ -1,101 +0,0 @@ | |||||||
| import * as assert from 'assert' |  | ||||||
| import * as core from '@actions/core' |  | ||||||
| import * as fs from 'fs' |  | ||||||
| import * as fsHelper from './fs-helper' |  | ||||||
| import * as io from '@actions/io' |  | ||||||
| import * as path from 'path' |  | ||||||
| import {IGitCommandManager} from './git-command-manager' |  | ||||||
| import {IGitSourceSettings} from './git-source-settings' |  | ||||||
|  |  | ||||||
| export async function prepareExistingDirectory( |  | ||||||
|   git: IGitCommandManager | undefined, |  | ||||||
|   repositoryPath: string, |  | ||||||
|   repositoryUrl: string, |  | ||||||
|   clean: boolean |  | ||||||
| ): Promise<void> { |  | ||||||
|   assert.ok(repositoryPath, 'Expected repositoryPath to be defined') |  | ||||||
|   assert.ok(repositoryUrl, 'Expected repositoryUrl to be defined') |  | ||||||
|  |  | ||||||
|   // Indicates whether to delete the directory contents |  | ||||||
|   let remove = false |  | ||||||
|  |  | ||||||
|   // Check whether using git or REST API |  | ||||||
|   if (!git) { |  | ||||||
|     remove = true |  | ||||||
|   } |  | ||||||
|   // Fetch URL does not match |  | ||||||
|   else if ( |  | ||||||
|     !fsHelper.directoryExistsSync(path.join(repositoryPath, '.git')) || |  | ||||||
|     repositoryUrl !== (await git.tryGetFetchUrl()) |  | ||||||
|   ) { |  | ||||||
|     remove = true |  | ||||||
|   } else { |  | ||||||
|     // Delete any index.lock and shallow.lock left by a previously canceled run or crashed git process |  | ||||||
|     const lockPaths = [ |  | ||||||
|       path.join(repositoryPath, '.git', 'index.lock'), |  | ||||||
|       path.join(repositoryPath, '.git', 'shallow.lock') |  | ||||||
|     ] |  | ||||||
|     for (const lockPath of lockPaths) { |  | ||||||
|       try { |  | ||||||
|         await io.rmRF(lockPath) |  | ||||||
|       } catch (error) { |  | ||||||
|         core.debug(`Unable to delete '${lockPath}'. ${error.message}`) |  | ||||||
|       } |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     try { |  | ||||||
|       core.startGroup('Removing previously created refs, to avoid conflicts') |  | ||||||
|       // Checkout detached HEAD |  | ||||||
|       if (!(await git.isDetached())) { |  | ||||||
|         await git.checkoutDetach() |  | ||||||
|       } |  | ||||||
|  |  | ||||||
|       // Remove all refs/heads/* |  | ||||||
|       let branches = await git.branchList(false) |  | ||||||
|       for (const branch of branches) { |  | ||||||
|         await git.branchDelete(false, branch) |  | ||||||
|       } |  | ||||||
|  |  | ||||||
|       // Remove all refs/remotes/origin/* to avoid conflicts |  | ||||||
|       branches = await git.branchList(true) |  | ||||||
|       for (const branch of branches) { |  | ||||||
|         await git.branchDelete(true, branch) |  | ||||||
|       } |  | ||||||
|       core.endGroup() |  | ||||||
|  |  | ||||||
|       // Clean |  | ||||||
|       if (clean) { |  | ||||||
|         core.startGroup('Cleaning the repository') |  | ||||||
|         if (!(await git.tryClean())) { |  | ||||||
|           core.debug( |  | ||||||
|             `The clean command failed. This might be caused by: 1) path too long, 2) permission issue, or 3) file in use. For futher investigation, manually run 'git clean -ffdx' on the directory '${repositoryPath}'.` |  | ||||||
|           ) |  | ||||||
|           remove = true |  | ||||||
|         } else if (!(await git.tryReset())) { |  | ||||||
|           remove = true |  | ||||||
|         } |  | ||||||
|         core.endGroup() |  | ||||||
|  |  | ||||||
|         if (remove) { |  | ||||||
|           core.warning( |  | ||||||
|             `Unable to clean or reset the repository. The repository will be recreated instead.` |  | ||||||
|           ) |  | ||||||
|         } |  | ||||||
|       } |  | ||||||
|     } catch (error) { |  | ||||||
|       core.warning( |  | ||||||
|         `Unable to prepare the existing repository. The repository will be recreated instead.` |  | ||||||
|       ) |  | ||||||
|       remove = true |  | ||||||
|     } |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   if (remove) { |  | ||||||
|     // Delete the contents of the directory. Don't delete the directory itself |  | ||||||
|     // since it might be the current working directory. |  | ||||||
|     core.info(`Deleting the contents of '${repositoryPath}'`) |  | ||||||
|     for (const file of await fs.promises.readdir(repositoryPath)) { |  | ||||||
|       await io.rmRF(path.join(repositoryPath, file)) |  | ||||||
|     } |  | ||||||
|   } |  | ||||||
| } |  | ||||||
| @@ -1,23 +1,38 @@ | |||||||
| import * as core from '@actions/core' | import * as core from '@actions/core' | ||||||
|  | import * as fs from 'fs' | ||||||
| import * as fsHelper from './fs-helper' | import * as fsHelper from './fs-helper' | ||||||
| import * as gitAuthHelper from './git-auth-helper' |  | ||||||
| import * as gitCommandManager from './git-command-manager' | import * as gitCommandManager from './git-command-manager' | ||||||
| import * as gitDirectoryHelper from './git-directory-helper' |  | ||||||
| import * as githubApiHelper from './github-api-helper' | import * as githubApiHelper from './github-api-helper' | ||||||
| import * as io from '@actions/io' | import * as io from '@actions/io' | ||||||
| import * as path from 'path' | import * as path from 'path' | ||||||
| import * as refHelper from './ref-helper' | import * as refHelper from './ref-helper' | ||||||
| import * as stateHelper from './state-helper' | import * as stateHelper from './state-helper' | ||||||
| import * as urlHelper from './url-helper' |  | ||||||
| import {IGitCommandManager} from './git-command-manager' | import {IGitCommandManager} from './git-command-manager' | ||||||
| import {IGitSourceSettings} from './git-source-settings' |  | ||||||
|  |  | ||||||
| export async function getSource(settings: IGitSourceSettings): Promise<void> { | const serverUrl = 'https://github.com/' | ||||||
|  | const authConfigKey = `http.${serverUrl}.extraheader` | ||||||
|  |  | ||||||
|  | export interface ISourceSettings { | ||||||
|  |   repositoryPath: string | ||||||
|  |   repositoryOwner: string | ||||||
|  |   repositoryName: string | ||||||
|  |   ref: string | ||||||
|  |   commit: string | ||||||
|  |   clean: boolean | ||||||
|  |   fetchDepth: number | ||||||
|  |   lfs: boolean | ||||||
|  |   authToken: string | ||||||
|  |   persistCredentials: boolean | ||||||
|  | } | ||||||
|  |  | ||||||
|  | export async function getSource(settings: ISourceSettings): Promise<void> { | ||||||
|   // Repository URL |   // Repository URL | ||||||
|   core.info( |   core.info( | ||||||
|     `Syncing repository: ${settings.repositoryOwner}/${settings.repositoryName}` |     `Syncing repository: ${settings.repositoryOwner}/${settings.repositoryName}` | ||||||
|   ) |   ) | ||||||
|   const repositoryUrl = urlHelper.getFetchUrl(settings) |   const repositoryUrl = `https://github.com/${encodeURIComponent( | ||||||
|  |     settings.repositoryOwner | ||||||
|  |   )}/${encodeURIComponent(settings.repositoryName)}` | ||||||
|  |  | ||||||
|   // Remove conflicting file path |   // Remove conflicting file path | ||||||
|   if (fsHelper.fileExistsSync(settings.repositoryPath)) { |   if (fsHelper.fileExistsSync(settings.repositoryPath)) { | ||||||
| @@ -32,13 +47,11 @@ export async function getSource(settings: IGitSourceSettings): Promise<void> { | |||||||
|   } |   } | ||||||
|  |  | ||||||
|   // Git command manager |   // Git command manager | ||||||
|   core.startGroup('Getting Git version info') |  | ||||||
|   const git = await getGitCommandManager(settings) |   const git = await getGitCommandManager(settings) | ||||||
|   core.endGroup() |  | ||||||
|  |  | ||||||
|   // Prepare existing directory, otherwise recreate |   // Prepare existing directory, otherwise recreate | ||||||
|   if (isExisting) { |   if (isExisting) { | ||||||
|     await gitDirectoryHelper.prepareExistingDirectory( |     await prepareExistingDirectory( | ||||||
|       git, |       git, | ||||||
|       settings.repositoryPath, |       settings.repositoryPath, | ||||||
|       repositoryUrl, |       repositoryUrl, | ||||||
| @@ -52,16 +65,6 @@ export async function getSource(settings: IGitSourceSettings): Promise<void> { | |||||||
|     core.info( |     core.info( | ||||||
|       `To create a local Git repository instead, add Git ${gitCommandManager.MinimumGitVersion} or higher to the PATH` |       `To create a local Git repository instead, add Git ${gitCommandManager.MinimumGitVersion} or higher to the PATH` | ||||||
|     ) |     ) | ||||||
|     if (settings.submodules) { |  | ||||||
|       throw new Error( |  | ||||||
|         `Input 'submodules' not supported when falling back to download using the GitHub REST API. To create a local Git repository instead, add Git ${gitCommandManager.MinimumGitVersion} or higher to the PATH.` |  | ||||||
|       ) |  | ||||||
|     } else if (settings.sshKey) { |  | ||||||
|       throw new Error( |  | ||||||
|         `Input 'ssh-key' not supported when falling back to download using the GitHub REST API. To create a local Git repository instead, add Git ${gitCommandManager.MinimumGitVersion} or higher to the PATH.` |  | ||||||
|       ) |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     await githubApiHelper.downloadRepository( |     await githubApiHelper.downloadRepository( | ||||||
|       settings.authToken, |       settings.authToken, | ||||||
|       settings.repositoryOwner, |       settings.repositoryOwner, | ||||||
| @@ -70,9 +73,7 @@ export async function getSource(settings: IGitSourceSettings): Promise<void> { | |||||||
|       settings.commit, |       settings.commit, | ||||||
|       settings.repositoryPath |       settings.repositoryPath | ||||||
|     ) |     ) | ||||||
|     return |   } else { | ||||||
|   } |  | ||||||
|  |  | ||||||
|     // Save state for POST action |     // Save state for POST action | ||||||
|     stateHelper.setRepositoryPath(settings.repositoryPath) |     stateHelper.setRepositoryPath(settings.repositoryPath) | ||||||
|  |  | ||||||
| @@ -80,27 +81,23 @@ export async function getSource(settings: IGitSourceSettings): Promise<void> { | |||||||
|     if ( |     if ( | ||||||
|       !fsHelper.directoryExistsSync(path.join(settings.repositoryPath, '.git')) |       !fsHelper.directoryExistsSync(path.join(settings.repositoryPath, '.git')) | ||||||
|     ) { |     ) { | ||||||
|     core.startGroup('Initializing the repository') |  | ||||||
|       await git.init() |       await git.init() | ||||||
|       await git.remoteAdd('origin', repositoryUrl) |       await git.remoteAdd('origin', repositoryUrl) | ||||||
|     core.endGroup() |  | ||||||
|     } |     } | ||||||
|  |  | ||||||
|     // Disable automatic garbage collection |     // Disable automatic garbage collection | ||||||
|   core.startGroup('Disabling automatic garbage collection') |  | ||||||
|     if (!(await git.tryDisableAutomaticGarbageCollection())) { |     if (!(await git.tryDisableAutomaticGarbageCollection())) { | ||||||
|       core.warning( |       core.warning( | ||||||
|         `Unable to turn off git automatic garbage collection. The git fetch operation may trigger garbage collection and cause a delay.` |         `Unable to turn off git automatic garbage collection. The git fetch operation may trigger garbage collection and cause a delay.` | ||||||
|       ) |       ) | ||||||
|     } |     } | ||||||
|   core.endGroup() |  | ||||||
|  |  | ||||||
|   const authHelper = gitAuthHelper.createAuthHelper(git, settings) |     // Remove possible previous extraheader | ||||||
|  |     await removeGitConfig(git, authConfigKey) | ||||||
|  |  | ||||||
|     try { |     try { | ||||||
|     // Configure auth |       // Config extraheader | ||||||
|     core.startGroup('Setting up auth') |       await configureAuthToken(git, settings.authToken) | ||||||
|     await authHelper.configureAuth() |  | ||||||
|     core.endGroup() |  | ||||||
|  |  | ||||||
|       // LFS install |       // LFS install | ||||||
|       if (settings.lfs) { |       if (settings.lfs) { | ||||||
| @@ -108,75 +105,32 @@ export async function getSource(settings: IGitSourceSettings): Promise<void> { | |||||||
|       } |       } | ||||||
|  |  | ||||||
|       // Fetch |       // Fetch | ||||||
|     core.startGroup('Fetching the repository') |  | ||||||
|       const refSpec = refHelper.getRefSpec(settings.ref, settings.commit) |       const refSpec = refHelper.getRefSpec(settings.ref, settings.commit) | ||||||
|       await git.fetch(settings.fetchDepth, refSpec) |       await git.fetch(settings.fetchDepth, refSpec) | ||||||
|     core.endGroup() |  | ||||||
|  |  | ||||||
|       // Checkout info |       // Checkout info | ||||||
|     core.startGroup('Determining the checkout info') |  | ||||||
|       const checkoutInfo = await refHelper.getCheckoutInfo( |       const checkoutInfo = await refHelper.getCheckoutInfo( | ||||||
|         git, |         git, | ||||||
|         settings.ref, |         settings.ref, | ||||||
|         settings.commit |         settings.commit | ||||||
|       ) |       ) | ||||||
|     core.endGroup() |  | ||||||
|  |  | ||||||
|       // LFS fetch |       // LFS fetch | ||||||
|       // Explicit lfs-fetch to avoid slow checkout (fetches one lfs object at a time). |       // Explicit lfs-fetch to avoid slow checkout (fetches one lfs object at a time). | ||||||
|       // Explicit lfs fetch will fetch lfs objects in parallel. |       // Explicit lfs fetch will fetch lfs objects in parallel. | ||||||
|       if (settings.lfs) { |       if (settings.lfs) { | ||||||
|       core.startGroup('Fetching LFS objects') |  | ||||||
|         await git.lfsFetch(checkoutInfo.startPoint || checkoutInfo.ref) |         await git.lfsFetch(checkoutInfo.startPoint || checkoutInfo.ref) | ||||||
|       core.endGroup() |  | ||||||
|       } |       } | ||||||
|  |  | ||||||
|       // Checkout |       // Checkout | ||||||
|     core.startGroup('Checking out the ref') |  | ||||||
|       await git.checkout(checkoutInfo.ref, checkoutInfo.startPoint) |       await git.checkout(checkoutInfo.ref, checkoutInfo.startPoint) | ||||||
|     core.endGroup() |  | ||||||
|  |  | ||||||
|     // Submodules |  | ||||||
|     if (settings.submodules) { |  | ||||||
|       try { |  | ||||||
|         // Temporarily override global config |  | ||||||
|         core.startGroup('Setting up auth for fetching submodules') |  | ||||||
|         await authHelper.configureGlobalAuth() |  | ||||||
|         core.endGroup() |  | ||||||
|  |  | ||||||
|         // Checkout submodules |  | ||||||
|         core.startGroup('Fetching submodules') |  | ||||||
|         await git.submoduleSync(settings.nestedSubmodules) |  | ||||||
|         await git.submoduleUpdate( |  | ||||||
|           settings.fetchDepth, |  | ||||||
|           settings.nestedSubmodules |  | ||||||
|         ) |  | ||||||
|         await git.submoduleForeach( |  | ||||||
|           'git config --local gc.auto 0', |  | ||||||
|           settings.nestedSubmodules |  | ||||||
|         ) |  | ||||||
|         core.endGroup() |  | ||||||
|  |  | ||||||
|         // Persist credentials |  | ||||||
|         if (settings.persistCredentials) { |  | ||||||
|           core.startGroup('Persisting credentials for submodules') |  | ||||||
|           await authHelper.configureSubmoduleAuth() |  | ||||||
|           core.endGroup() |  | ||||||
|         } |  | ||||||
|       } finally { |  | ||||||
|         // Remove temporary global config override |  | ||||||
|         await authHelper.removeGlobalAuth() |  | ||||||
|       } |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|       // Dump some info about the checked out commit |       // Dump some info about the checked out commit | ||||||
|       await git.log1() |       await git.log1() | ||||||
|     } finally { |     } finally { | ||||||
|     // Remove auth |  | ||||||
|       if (!settings.persistCredentials) { |       if (!settings.persistCredentials) { | ||||||
|       core.startGroup('Removing auth') |         await removeGitConfig(git, authConfigKey) | ||||||
|       await authHelper.removeAuth() |       } | ||||||
|       core.endGroup() |  | ||||||
|     } |     } | ||||||
|   } |   } | ||||||
| } | } | ||||||
| @@ -192,22 +146,22 @@ export async function cleanup(repositoryPath: string): Promise<void> { | |||||||
|  |  | ||||||
|   let git: IGitCommandManager |   let git: IGitCommandManager | ||||||
|   try { |   try { | ||||||
|     git = await gitCommandManager.createCommandManager(repositoryPath, false) |     git = await gitCommandManager.CreateCommandManager(repositoryPath, false) | ||||||
|   } catch { |   } catch { | ||||||
|     return |     return | ||||||
|   } |   } | ||||||
|  |  | ||||||
|   // Remove auth |   // Remove extraheader | ||||||
|   const authHelper = gitAuthHelper.createAuthHelper(git) |   await removeGitConfig(git, authConfigKey) | ||||||
|   await authHelper.removeAuth() |  | ||||||
| } | } | ||||||
|  |  | ||||||
| async function getGitCommandManager( | async function getGitCommandManager( | ||||||
|   settings: IGitSourceSettings |   settings: ISourceSettings | ||||||
| ): Promise<IGitCommandManager | undefined> { | ): Promise<IGitCommandManager> { | ||||||
|   core.info(`Working directory is '${settings.repositoryPath}'`) |   core.info(`Working directory is '${settings.repositoryPath}'`) | ||||||
|  |   let git = (null as unknown) as IGitCommandManager | ||||||
|   try { |   try { | ||||||
|     return await gitCommandManager.createCommandManager( |     return await gitCommandManager.CreateCommandManager( | ||||||
|       settings.repositoryPath, |       settings.repositoryPath, | ||||||
|       settings.lfs |       settings.lfs | ||||||
|     ) |     ) | ||||||
| @@ -218,6 +172,138 @@ async function getGitCommandManager( | |||||||
|     } |     } | ||||||
|  |  | ||||||
|     // Otherwise fallback to REST API |     // Otherwise fallback to REST API | ||||||
|     return undefined |     return (null as unknown) as IGitCommandManager | ||||||
|  |   } | ||||||
|  | } | ||||||
|  |  | ||||||
|  | async function prepareExistingDirectory( | ||||||
|  |   git: IGitCommandManager, | ||||||
|  |   repositoryPath: string, | ||||||
|  |   repositoryUrl: string, | ||||||
|  |   clean: boolean | ||||||
|  | ): Promise<void> { | ||||||
|  |   let remove = false | ||||||
|  |  | ||||||
|  |   // Check whether using git or REST API | ||||||
|  |   if (!git) { | ||||||
|  |     remove = true | ||||||
|  |   } | ||||||
|  |   // Fetch URL does not match | ||||||
|  |   else if ( | ||||||
|  |     !fsHelper.directoryExistsSync(path.join(repositoryPath, '.git')) || | ||||||
|  |     repositoryUrl !== (await git.tryGetFetchUrl()) | ||||||
|  |   ) { | ||||||
|  |     remove = true | ||||||
|  |   } else { | ||||||
|  |     // Delete any index.lock and shallow.lock left by a previously canceled run or crashed git process | ||||||
|  |     const lockPaths = [ | ||||||
|  |       path.join(repositoryPath, '.git', 'index.lock'), | ||||||
|  |       path.join(repositoryPath, '.git', 'shallow.lock') | ||||||
|  |     ] | ||||||
|  |     for (const lockPath of lockPaths) { | ||||||
|  |       try { | ||||||
|  |         await io.rmRF(lockPath) | ||||||
|  |       } catch (error) { | ||||||
|  |         core.debug(`Unable to delete '${lockPath}'. ${error.message}`) | ||||||
|  |       } | ||||||
|  |     } | ||||||
|  |  | ||||||
|  |     try { | ||||||
|  |       // Checkout detached HEAD | ||||||
|  |       if (!(await git.isDetached())) { | ||||||
|  |         await git.checkoutDetach() | ||||||
|  |       } | ||||||
|  |  | ||||||
|  |       // Remove all refs/heads/* | ||||||
|  |       let branches = await git.branchList(false) | ||||||
|  |       for (const branch of branches) { | ||||||
|  |         await git.branchDelete(false, branch) | ||||||
|  |       } | ||||||
|  |  | ||||||
|  |       // Remove all refs/remotes/origin/* to avoid conflicts | ||||||
|  |       branches = await git.branchList(true) | ||||||
|  |       for (const branch of branches) { | ||||||
|  |         await git.branchDelete(true, branch) | ||||||
|  |       } | ||||||
|  |  | ||||||
|  |       // Clean | ||||||
|  |       if (clean) { | ||||||
|  |         if (!(await git.tryClean())) { | ||||||
|  |           core.debug( | ||||||
|  |             `The clean command failed. This might be caused by: 1) path too long, 2) permission issue, or 3) file in use. For futher investigation, manually run 'git clean -ffdx' on the directory '${repositoryPath}'.` | ||||||
|  |           ) | ||||||
|  |           remove = true | ||||||
|  |         } else if (!(await git.tryReset())) { | ||||||
|  |           remove = true | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         if (remove) { | ||||||
|  |           core.warning( | ||||||
|  |             `Unable to clean or reset the repository. The repository will be recreated instead.` | ||||||
|  |           ) | ||||||
|  |         } | ||||||
|  |       } | ||||||
|  |     } catch (error) { | ||||||
|  |       core.warning( | ||||||
|  |         `Unable to prepare the existing repository. The repository will be recreated instead.` | ||||||
|  |       ) | ||||||
|  |       remove = true | ||||||
|  |     } | ||||||
|  |   } | ||||||
|  |  | ||||||
|  |   if (remove) { | ||||||
|  |     // Delete the contents of the directory. Don't delete the directory itself | ||||||
|  |     // since it might be the current working directory. | ||||||
|  |     core.info(`Deleting the contents of '${repositoryPath}'`) | ||||||
|  |     for (const file of await fs.promises.readdir(repositoryPath)) { | ||||||
|  |       await io.rmRF(path.join(repositoryPath, file)) | ||||||
|  |     } | ||||||
|  |   } | ||||||
|  | } | ||||||
|  |  | ||||||
|  | async function configureAuthToken( | ||||||
|  |   git: IGitCommandManager, | ||||||
|  |   authToken: string | ||||||
|  | ): Promise<void> { | ||||||
|  |   // Configure a placeholder value. This approach avoids the credential being captured | ||||||
|  |   // by process creation audit events, which are commonly logged. For more information, | ||||||
|  |   // refer to https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/component-updates/command-line-process-auditing | ||||||
|  |   const placeholder = `AUTHORIZATION: basic ***` | ||||||
|  |   await git.config(authConfigKey, placeholder) | ||||||
|  |  | ||||||
|  |   // Determine the basic credential value | ||||||
|  |   const basicCredential = Buffer.from( | ||||||
|  |     `x-access-token:${authToken}`, | ||||||
|  |     'utf8' | ||||||
|  |   ).toString('base64') | ||||||
|  |   core.setSecret(basicCredential) | ||||||
|  |  | ||||||
|  |   // Replace the value in the config file | ||||||
|  |   const configPath = path.join(git.getWorkingDirectory(), '.git', 'config') | ||||||
|  |   let content = (await fs.promises.readFile(configPath)).toString() | ||||||
|  |   const placeholderIndex = content.indexOf(placeholder) | ||||||
|  |   if ( | ||||||
|  |     placeholderIndex < 0 || | ||||||
|  |     placeholderIndex != content.lastIndexOf(placeholder) | ||||||
|  |   ) { | ||||||
|  |     throw new Error('Unable to replace auth placeholder in .git/config') | ||||||
|  |   } | ||||||
|  |   content = content.replace( | ||||||
|  |     placeholder, | ||||||
|  |     `AUTHORIZATION: basic ${basicCredential}` | ||||||
|  |   ) | ||||||
|  |   await fs.promises.writeFile(configPath, content) | ||||||
|  | } | ||||||
|  |  | ||||||
|  | async function removeGitConfig( | ||||||
|  |   git: IGitCommandManager, | ||||||
|  |   configKey: string | ||||||
|  | ): Promise<void> { | ||||||
|  |   if ( | ||||||
|  |     (await git.configExists(configKey)) && | ||||||
|  |     !(await git.tryConfigUnset(configKey)) | ||||||
|  |   ) { | ||||||
|  |     // Load the config contents | ||||||
|  |     core.warning(`Failed to remove '${configKey}' from the git config`) | ||||||
|   } |   } | ||||||
| } | } | ||||||
|   | |||||||
| @@ -1,76 +0,0 @@ | |||||||
| export interface IGitSourceSettings { |  | ||||||
|   /** |  | ||||||
|    * The location on disk where the repository will be placed |  | ||||||
|    */ |  | ||||||
|   repositoryPath: string |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * The repository owner |  | ||||||
|    */ |  | ||||||
|   repositoryOwner: string |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * The repository name |  | ||||||
|    */ |  | ||||||
|   repositoryName: string |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * The ref to fetch |  | ||||||
|    */ |  | ||||||
|   ref: string |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * The commit to checkout |  | ||||||
|    */ |  | ||||||
|   commit: string |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * Indicates whether to clean the repository |  | ||||||
|    */ |  | ||||||
|   clean: boolean |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * The depth when fetching |  | ||||||
|    */ |  | ||||||
|   fetchDepth: number |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * Indicates whether to fetch LFS objects |  | ||||||
|    */ |  | ||||||
|   lfs: boolean |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * Indicates whether to checkout submodules |  | ||||||
|    */ |  | ||||||
|   submodules: boolean |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * Indicates whether to recursively checkout submodules |  | ||||||
|    */ |  | ||||||
|   nestedSubmodules: boolean |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * The auth token to use when fetching the repository |  | ||||||
|    */ |  | ||||||
|   authToken: string |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * The SSH key to configure |  | ||||||
|    */ |  | ||||||
|   sshKey: string |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * Additional SSH known hosts |  | ||||||
|    */ |  | ||||||
|   sshKnownHosts: string |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * Indicates whether the server must be a known host |  | ||||||
|    */ |  | ||||||
|   sshStrict: boolean |  | ||||||
|  |  | ||||||
|   /** |  | ||||||
|    * Indicates whether to persist the credentials on disk to enable scripting authenticated git commands |  | ||||||
|    */ |  | ||||||
|   persistCredentials: boolean |  | ||||||
| } |  | ||||||
| @@ -6,7 +6,6 @@ import * as io from '@actions/io' | |||||||
| import * as path from 'path' | import * as path from 'path' | ||||||
| import * as retryHelper from './retry-helper' | import * as retryHelper from './retry-helper' | ||||||
| import * as toolCache from '@actions/tool-cache' | import * as toolCache from '@actions/tool-cache' | ||||||
| import * as urlHelper from './url-helper' |  | ||||||
| import {default as uuid} from 'uuid/v4' | import {default as uuid} from 'uuid/v4' | ||||||
| import {ReposGetArchiveLinkParams} from '@octokit/rest' | import {ReposGetArchiveLinkParams} from '@octokit/rest' | ||||||
|  |  | ||||||
| @@ -75,7 +74,7 @@ async function downloadArchive( | |||||||
|   ref: string, |   ref: string, | ||||||
|   commit: string |   commit: string | ||||||
| ): Promise<Buffer> { | ): Promise<Buffer> { | ||||||
|   const octokit = new github.GitHub(authToken, {baseUrl: urlHelper.getApiUrl()}) |   const octokit = new github.GitHub(authToken) | ||||||
|   const params: ReposGetArchiveLinkParams = { |   const params: ReposGetArchiveLinkParams = { | ||||||
|     owner: owner, |     owner: owner, | ||||||
|     repo: repo, |     repo: repo, | ||||||
|   | |||||||
| @@ -2,10 +2,10 @@ import * as core from '@actions/core' | |||||||
| import * as fsHelper from './fs-helper' | import * as fsHelper from './fs-helper' | ||||||
| import * as github from '@actions/github' | import * as github from '@actions/github' | ||||||
| import * as path from 'path' | import * as path from 'path' | ||||||
| import {IGitSourceSettings} from './git-source-settings' | import {ISourceSettings} from './git-source-provider' | ||||||
|  |  | ||||||
| export function getInputs(): IGitSourceSettings { | export function getInputs(): ISourceSettings { | ||||||
|   const result = ({} as unknown) as IGitSourceSettings |   const result = ({} as unknown) as ISourceSettings | ||||||
|  |  | ||||||
|   // GitHub workspace |   // GitHub workspace | ||||||
|   let githubWorkspacePath = process.env['GITHUB_WORKSPACE'] |   let githubWorkspacePath = process.env['GITHUB_WORKSPACE'] | ||||||
| @@ -85,6 +85,13 @@ export function getInputs(): IGitSourceSettings { | |||||||
|   result.clean = (core.getInput('clean') || 'true').toUpperCase() === 'TRUE' |   result.clean = (core.getInput('clean') || 'true').toUpperCase() === 'TRUE' | ||||||
|   core.debug(`clean = ${result.clean}`) |   core.debug(`clean = ${result.clean}`) | ||||||
|  |  | ||||||
|  |   // Submodules | ||||||
|  |   if (core.getInput('submodules')) { | ||||||
|  |     throw new Error( | ||||||
|  |       "The input 'submodules' is not supported in actions/checkout@v2" | ||||||
|  |     ) | ||||||
|  |   } | ||||||
|  |  | ||||||
|   // Fetch depth |   // Fetch depth | ||||||
|   result.fetchDepth = Math.floor(Number(core.getInput('fetch-depth') || '1')) |   result.fetchDepth = Math.floor(Number(core.getInput('fetch-depth') || '1')) | ||||||
|   if (isNaN(result.fetchDepth) || result.fetchDepth < 0) { |   if (isNaN(result.fetchDepth) || result.fetchDepth < 0) { | ||||||
| @@ -96,28 +103,9 @@ export function getInputs(): IGitSourceSettings { | |||||||
|   result.lfs = (core.getInput('lfs') || 'false').toUpperCase() === 'TRUE' |   result.lfs = (core.getInput('lfs') || 'false').toUpperCase() === 'TRUE' | ||||||
|   core.debug(`lfs = ${result.lfs}`) |   core.debug(`lfs = ${result.lfs}`) | ||||||
|  |  | ||||||
|   // Submodules |  | ||||||
|   result.submodules = false |  | ||||||
|   result.nestedSubmodules = false |  | ||||||
|   const submodulesString = (core.getInput('submodules') || '').toUpperCase() |  | ||||||
|   if (submodulesString == 'RECURSIVE') { |  | ||||||
|     result.submodules = true |  | ||||||
|     result.nestedSubmodules = true |  | ||||||
|   } else if (submodulesString == 'TRUE') { |  | ||||||
|     result.submodules = true |  | ||||||
|   } |  | ||||||
|   core.debug(`submodules = ${result.submodules}`) |  | ||||||
|   core.debug(`recursive submodules = ${result.nestedSubmodules}`) |  | ||||||
|  |  | ||||||
|   // Auth token |   // Auth token | ||||||
|   result.authToken = core.getInput('token') |   result.authToken = core.getInput('token') | ||||||
|  |  | ||||||
|   // SSH |  | ||||||
|   result.sshKey = core.getInput('ssh-key') |  | ||||||
|   result.sshKnownHosts = core.getInput('ssh-known-hosts') |  | ||||||
|   result.sshStrict = |  | ||||||
|     (core.getInput('ssh-strict') || 'true').toUpperCase() === 'TRUE' |  | ||||||
|  |  | ||||||
|   // Persist credentials |   // Persist credentials | ||||||
|   result.persistCredentials = |   result.persistCredentials = | ||||||
|     (core.getInput('persist-credentials') || 'false').toUpperCase() === 'TRUE' |     (core.getInput('persist-credentials') || 'false').toUpperCase() === 'TRUE' | ||||||
|   | |||||||
| @@ -59,17 +59,13 @@ function updateUsage( | |||||||
|  |  | ||||||
|     // Constrain the width of the description |     // Constrain the width of the description | ||||||
|     const width = 80 |     const width = 80 | ||||||
|     let description = (input.description as string) |     let description = input.description as string | ||||||
|       .trimRight() |  | ||||||
|       .replace(/\r\n/g, '\n') // Convert CR to LF |  | ||||||
|       .replace(/ +/g, ' ') //    Squash consecutive spaces |  | ||||||
|       .replace(/ \n/g, '\n') //  Squash space followed by newline |  | ||||||
|     while (description) { |     while (description) { | ||||||
|       // Longer than width? Find a space to break apart |       // Longer than width? Find a space to break apart | ||||||
|       let segment: string = description |       let segment: string = description | ||||||
|       if (description.length > width) { |       if (description.length > width) { | ||||||
|         segment = description.substr(0, width + 1) |         segment = description.substr(0, width + 1) | ||||||
|         while (!segment.endsWith(' ') && !segment.endsWith('\n') && segment) { |         while (!segment.endsWith(' ') && segment) { | ||||||
|           segment = segment.substr(0, segment.length - 1) |           segment = segment.substr(0, segment.length - 1) | ||||||
|         } |         } | ||||||
|  |  | ||||||
| @@ -81,30 +77,15 @@ function updateUsage( | |||||||
|         segment = description |         segment = description | ||||||
|       } |       } | ||||||
|  |  | ||||||
|       // Check for newline |       description = description.substr(segment.length) // Remaining | ||||||
|       const newlineIndex = segment.indexOf('\n') |       segment = segment.trimRight() // Trim the trailing space | ||||||
|       if (newlineIndex >= 0) { |       newReadme.push(`    # ${segment}`) | ||||||
|         segment = segment.substr(0, newlineIndex + 1) |  | ||||||
|       } |  | ||||||
|  |  | ||||||
|       // Append segment |  | ||||||
|       newReadme.push(`    # ${segment}`.trimRight()) |  | ||||||
|  |  | ||||||
|       // Remaining |  | ||||||
|       description = description.substr(segment.length) |  | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     // Input and default | ||||||
|     if (input.default !== undefined) { |     if (input.default !== undefined) { | ||||||
|       // Append blank line if description had paragraphs |  | ||||||
|       if ((input.description as string).trimRight().match(/\n[ ]*\r?\n/)) { |  | ||||||
|         newReadme.push(`    #`) |  | ||||||
|       } |  | ||||||
|  |  | ||||||
|       // Default |  | ||||||
|       newReadme.push(`    # Default: ${input.default}`) |       newReadme.push(`    # Default: ${input.default}`) | ||||||
|     } |     } | ||||||
|  |  | ||||||
|     // Input name |  | ||||||
|     newReadme.push(`    ${key}: ''`) |     newReadme.push(`    ${key}: ''`) | ||||||
|  |  | ||||||
|     firstInput = false |     firstInput = false | ||||||
|   | |||||||
| @@ -1,5 +0,0 @@ | |||||||
| export function escape(value: string): string { |  | ||||||
|   return value.replace(/[^a-zA-Z0-9_]/g, x => { |  | ||||||
|     return `\\${x}` |  | ||||||
|   }) |  | ||||||
| } |  | ||||||
| @@ -1,3 +1,4 @@ | |||||||
|  | import * as core from '@actions/core' | ||||||
| import * as coreCommand from '@actions/core/lib/command' | import * as coreCommand from '@actions/core/lib/command' | ||||||
|  |  | ||||||
| /** | /** | ||||||
| @@ -11,17 +12,6 @@ export const IsPost = !!process.env['STATE_isPost'] | |||||||
| export const RepositoryPath = | export const RepositoryPath = | ||||||
|   (process.env['STATE_repositoryPath'] as string) || '' |   (process.env['STATE_repositoryPath'] as string) || '' | ||||||
|  |  | ||||||
| /** |  | ||||||
|  * The SSH key path for the POST action. The value is empty during the MAIN action. |  | ||||||
|  */ |  | ||||||
| export const SshKeyPath = (process.env['STATE_sshKeyPath'] as string) || '' |  | ||||||
|  |  | ||||||
| /** |  | ||||||
|  * The SSH known hosts path for the POST action. The value is empty during the MAIN action. |  | ||||||
|  */ |  | ||||||
| export const SshKnownHostsPath = |  | ||||||
|   (process.env['STATE_sshKnownHostsPath'] as string) || '' |  | ||||||
|  |  | ||||||
| /** | /** | ||||||
|  * Save the repository path so the POST action can retrieve the value. |  * Save the repository path so the POST action can retrieve the value. | ||||||
|  */ |  */ | ||||||
| @@ -33,24 +23,6 @@ export function setRepositoryPath(repositoryPath: string) { | |||||||
|   ) |   ) | ||||||
| } | } | ||||||
|  |  | ||||||
| /** |  | ||||||
|  * Save the SSH key path so the POST action can retrieve the value. |  | ||||||
|  */ |  | ||||||
| export function setSshKeyPath(sshKeyPath: string) { |  | ||||||
|   coreCommand.issueCommand('save-state', {name: 'sshKeyPath'}, sshKeyPath) |  | ||||||
| } |  | ||||||
|  |  | ||||||
| /** |  | ||||||
|  * Save the SSH known hosts path so the POST action can retrieve the value. |  | ||||||
|  */ |  | ||||||
| export function setSshKnownHostsPath(sshKnownHostsPath: string) { |  | ||||||
|   coreCommand.issueCommand( |  | ||||||
|     'save-state', |  | ||||||
|     {name: 'sshKnownHostsPath'}, |  | ||||||
|     sshKnownHostsPath |  | ||||||
|   ) |  | ||||||
| } |  | ||||||
|  |  | ||||||
| // Publish a variable so that when the POST action runs, it can determine it should run the cleanup logic. | // Publish a variable so that when the POST action runs, it can determine it should run the cleanup logic. | ||||||
| // This is necessary since we don't have a separate entry point. | // This is necessary since we don't have a separate entry point. | ||||||
| if (!IsPost) { | if (!IsPost) { | ||||||
|   | |||||||
| @@ -1,28 +0,0 @@ | |||||||
| import * as assert from 'assert' |  | ||||||
| import {IGitSourceSettings} from './git-source-settings' |  | ||||||
| import {URL} from 'url' |  | ||||||
|  |  | ||||||
| export function getApiUrl(): string { |  | ||||||
|   return process.env['GITHUB_API_URL'] || 'https://api.github.com' |  | ||||||
| } |  | ||||||
|  |  | ||||||
| export function getFetchUrl(settings: IGitSourceSettings): string { |  | ||||||
|   assert.ok( |  | ||||||
|     settings.repositoryOwner, |  | ||||||
|     'settings.repositoryOwner must be defined' |  | ||||||
|   ) |  | ||||||
|   assert.ok(settings.repositoryName, 'settings.repositoryName must be defined') |  | ||||||
|   const serviceUrl = getServerUrl() |  | ||||||
|   const encodedOwner = encodeURIComponent(settings.repositoryOwner) |  | ||||||
|   const encodedName = encodeURIComponent(settings.repositoryName) |  | ||||||
|   if (settings.sshKey) { |  | ||||||
|     return `git@${serviceUrl.hostname}:${encodedOwner}/${encodedName}.git` |  | ||||||
|   } |  | ||||||
|  |  | ||||||
|   // "origin" is SCHEME://HOSTNAME[:PORT] |  | ||||||
|   return `${serviceUrl.origin}/${encodedOwner}/${encodedName}` |  | ||||||
| } |  | ||||||
|  |  | ||||||
| export function getServerUrl(): URL { |  | ||||||
|   return new URL(process.env['GITHUB_URL'] || 'https://github.com') |  | ||||||
| } |  | ||||||
		Reference in New Issue
	
	Block a user