diff --git a/action.yaml b/action.yaml index 20c31d5..ba88779 100644 --- a/action.yaml +++ b/action.yaml @@ -11,6 +11,10 @@ inputs: description: 'Branch receiving updates from the upstream repo, e.g. => main, master, prod' required: true + source_repo_token: + description: 'Input for passing secrets.GITHUB_TOKEN when disabling persistent auth in the checkout step' + required: false + upstream_repo_access_token: description: 'Token for accessing the remote repo through HTTPS authentication' required: false diff --git a/entry/config_and_run.sh b/entry/config_and_run.sh index db235cc..527d8dc 100755 --- a/entry/config_and_run.sh +++ b/entry/config_and_run.sh @@ -16,6 +16,12 @@ if [ -z "${GITHUB_ACTIONS}" ] || [ "${GITHUB_ACTIONS}" = false ]; then # region vars # Github login of the user initiating the workflow run GITHUB_ACTOR="aormsby" + + # TODO: figure out local mode defaults and use + # shellcheck disable=SC2034 + INPUT_SOURCE_REPO_TOKEN="" + # shellcheck disable=SC2034 + GITHUB_REPOSITORY="" # required vars (except token) # shellcheck disable=SC2034 diff --git a/run/push_updates.sh b/run/push_updates.sh index 6768b6f..e094c58 100644 --- a/run/push_updates.sh +++ b/run/push_updates.sh @@ -4,6 +4,13 @@ push_new_commits() { write_out -1 'Pushing synced data to source branch.' + # TODO: figure out hwo this would work in local mode... + # update origin url with token since it is not persisted during checkout step when syncing from a private repo + if [ -n "${INPUT_UPSTREAM_REPO_ACCESS_TOKEN}" ]; then + echo "github token - ${INPUT_SOURCE_REPO_TOKEN}" + git remote set-url origin "https://${GITHUB_ACTOR}:${INPUT_SOURCE_REPO_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" + fi + # shellcheck disable=SC2086 git push ${INPUT_SOURCE_PUSH_ARGS} origin "${INPUT_SOURCE_SYNC_BRANCH}" COMMAND_STATUS=$?