Set Authorization header for downloading update-job-proxy

This commit is contained in:
Michael B. Gale
2025-09-24 12:40:57 +01:00
parent efcf614b5d
commit d43f46c39c
2 changed files with 38 additions and 12 deletions

View File

@@ -49356,17 +49356,8 @@ var persistInputs = function() {
core4.saveState(persistedInputsKey, JSON.stringify(inputEnvironmentVariables));
};
// src/logging.ts
var core5 = __toESM(require_core());
function getActionsLogger() {
return core5;
}
// src/start-proxy.ts
var core7 = __toESM(require_core());
// src/api-client.ts
var core6 = __toESM(require_core());
var core5 = __toESM(require_core());
var githubUtils = __toESM(require_utils4());
var retry = __toESM(require_dist_node15());
var import_console_log_level = __toESM(require_console_log_level());
@@ -49391,6 +49382,23 @@ function getApiDetails() {
function getApiClient() {
return createApiClientWithDetails(getApiDetails());
}
function getAuthorizationHeaderFor(logger, apiDetails, url, purpose = "CodeQL tools") {
if (url.startsWith(`${apiDetails.url}/`) || apiDetails.apiURL && url.startsWith(`${apiDetails.apiURL}/`)) {
logger.debug(`Providing an authorization token to download ${purpose}.`);
return `token ${apiDetails.auth}`;
}
logger.debug(`Downloading ${purpose} without an authorization token.`);
return void 0;
}
// src/logging.ts
var core6 = __toESM(require_core());
function getActionsLogger() {
return core6;
}
// src/start-proxy.ts
var core7 = __toESM(require_core());
// src/defaults.json
var bundleVersion = "codeql-bundle-v2.23.1";
@@ -49682,10 +49690,17 @@ async function getProxyBinaryPath(logger) {
const proxyInfo = await getDownloadUrl(logger);
let proxyBin = toolcache.find(proxyFileName, proxyInfo.version);
if (!proxyBin) {
const apiDetails = getApiDetails();
const authorization = getAuthorizationHeaderFor(
logger,
apiDetails,
proxyInfo.url,
"`update-job-proxy`"
);
const temp = await toolcache.downloadTool(
proxyInfo.url,
void 0,
void 0,
authorization,
{
accept: "application/octet-stream"
}

View File

@@ -6,6 +6,7 @@ import * as toolcache from "@actions/tool-cache";
import { pki } from "node-forge";
import * as actionsUtil from "./actions-util";
import { getApiDetails, getAuthorizationHeaderFor } from "./api-client";
import { getActionsLogger, Logger } from "./logging";
import {
Credential,
@@ -192,10 +193,20 @@ async function getProxyBinaryPath(logger: Logger): Promise<string> {
let proxyBin = toolcache.find(proxyFileName, proxyInfo.version);
if (!proxyBin) {
// We only want to provide an authorization header if we are downloading
// from the same GitHub instance the Action is running on.
// This avoids leaking Enterprise tokens to dotcom.
const apiDetails = getApiDetails();
const authorization = getAuthorizationHeaderFor(
logger,
apiDetails,
proxyInfo.url,
"`update-job-proxy`",
);
const temp = await toolcache.downloadTool(
proxyInfo.url,
undefined,
undefined,
authorization,
{
accept: "application/octet-stream",
},