release: 1.0.2, and learn whether the built-in job token can publish
publish / npm (push) Successful in 5s

The publish step now tries the built-in Gitea job token first, prints which user it belongs to, falls back to NPM_TOKEN when the registry rejects it, and reports which token actually published. A 409 keeps meaning 'already published', so a re-run stays harmless.
This commit is contained in:
pyh
2026-09-30 14:29:02 +08:00
parent c842cd0118
commit 1a9165fa4f
3 changed files with 58 additions and 25 deletions
+54 -21
View File
@@ -88,32 +88,65 @@ jobs:
JOB_TOKEN: ${{ secrets.GITEA_TOKEN }}
run: |
set -eu
token="${NPM_TOKEN:-$JOB_TOKEN}"
if [ -z "$token" ]; then
echo "没有可用的发布令牌:请配置 NPM_TOKEN,或确认实例会注入 GITEA_TOKEN" >&2
exit 1
fi
# 作用域与默认注册表都指向本组织的 npm 仓库(默认注册表也要设,否则 npm 会拿
# registry.npmjs.org 的 packument 做“是否已发布”判断,甚至可能发错地方),
# 并把令牌写进本机 .npmrc。
# registry.npmjs.org 的 packument 做“是否已发布”判断,甚至可能发错地方)。
# 注意:npm 不允许用 `npm config get` 读回 _authToken(会报 protected),所以不打印它。
npm config set registry "${REGISTRY}"
npm config set @dsh-plugin:registry "${REGISTRY}"
npm config set "//gitea.iwake.top/api/packages/dsh-plugin/npm/:_authToken" "${token}"
echo "registry = $(npm config get registry)"
# 已发布的版本由注册表自己判定:Gitea 对同版本返回 409(package version already
# exists),npm 客户端在本地也会用 "cannot publish over the previously published
# versions" 拦下来。两种都算“本次无需发布”而不是失败;其余错误(E401/E403 等)照旧失败。
set +e
output="$(npm publish --registry "${REGISTRY}" --access public 2>&1)"
status=$?
set -e
printf '%s\n' "${output}"
if [ "${status}" -eq 0 ]; then
echo "已发布 ${{ steps.version.outputs.name }}@${{ steps.version.outputs.version }}"
elif printf '%s' "${output}" | grep -Eqi 'E409|already exists|previously published|cannot publish over'; then
echo "${{ steps.version.outputs.name }}@${{ steps.version.outputs.version }} 已存在,本次跳过(不算失败)"
# 内置任务令牌到底是谁、能不能写这个包命名空间:先打印身份,便于事后判断。
if [ -n "${JOB_TOKEN:-}" ]; then
server="${GITHUB_SERVER_URL:-https://gitea.iwake.top}"
who="$(curl -fsS -H "Authorization: token ${JOB_TOKEN}" "${server}/api/v1/user" 2>/dev/null | head -c 300 || true)"
echo "内置任务令牌身份:${who:-(查询失败,可能是 curl 不可用或令牌被拒)}"
else
exit "${status}"
echo "实例没有注入内置任务令牌(secrets.GITEA_TOKEN 为空)"
fi
RESULT=""
# 结果分类:published 成功 / exists 版本已存在(不视为失败)/ auth 令牌被拒 / error 其他
run_publish() {
label="$1"
token="$2"
LAST_LABEL="${label}"
echo "--- 用 ${label} 发布 ---"
npm config set "//gitea.iwake.top/api/packages/dsh-plugin/npm/:_authToken" "${token}"
set +e
output="$(npm publish --registry "${REGISTRY}" --access public 2>&1)"
status=$?
set -e
printf '%s\n' "${output}"
if [ "${status}" -eq 0 ]; then RESULT="published"; return 0; fi
if printf '%s' "${output}" | grep -Eqi 'E409|already exists|previously published|cannot publish over'; then RESULT="exists"; return 0; fi
if printf '%s' "${output}" | grep -Eqi 'E401|E403|EOTP|unauthorized|forbidden'; then RESULT="auth"; return 0; fi
RESULT="error"
return 1
}
if [ -n "${JOB_TOKEN:-}" ]; then
run_publish "内置任务令牌 GITEA_TOKEN" "${JOB_TOKEN}"
fi
if [ "${RESULT}" = "auth" ]; then
echo "内置任务令牌无法发布这个包(见上面的错误码),改用 NPM_TOKEN 重试"
RESULT=""
if [ -n "${NPM_TOKEN:-}" ]; then
run_publish "个人访问令牌 NPM_TOKEN" "${NPM_TOKEN}"
else
echo "没有配置 NPM_TOKEN,无处回退" >&2
exit 1
fi
fi
case "${RESULT}" in
published)
echo "已发布 ${{ steps.version.outputs.name }}@${{ steps.version.outputs.version }}(本次用的是 ${LAST_LABEL:-令牌})"
;;
exists)
echo "${{ steps.version.outputs.name }}@${{ steps.version.outputs.version }} 已存在,本次跳过(不算失败)"
;;
*)
echo "发布失败" >&2
exit 1
;;
esac
+3 -3
View File
@@ -58,16 +58,16 @@ DSH 的 **插件 → 添加插件** 里有两个输入,含义不同:
在上面的输入框里填:
```text
https://gitea.iwake.top/dsh-plugin/session-delete.git#v1.0.1
https://gitea.iwake.top/dsh-plugin/session-delete.git#v1.0.2
```
`#` 后面可以跟标签或提交,用来锁定版本;不写则取默认分支。仓库是公开的,不需要凭据,也不需要改安装源。
想跟随 1.x 的最新版本,可以把后缀写成 `#semver:^1.0.1`——pnpm 会按仓库里的标签挑最高的 1.x(当前即 v1.0.1 那个提交),以后发了 v1.0.2,移除旧版本再装一次就能拿到。
想跟随 1.x 的最新版本,可以把后缀写成 `#semver:^1.0.2`——pnpm 会按仓库里的标签挑最高的 1.x(当前即 v1.0.2 那个提交),以后发了 v1.0.3,移除旧版本再装一次就能拿到。
### 2. 本地 tgz
把 [session-delete-1.0.1.tgz](https://gitea.iwake.top/api/packages/dsh-plugin/npm/@dsh-plugin%2Fsession-delete/-/1.0.1/session-delete-1.0.1.tgz) 下载到运行 DSH 的机器上,把它的绝对路径填进上面的输入框。
把 [session-delete-1.0.2.tgz](https://gitea.iwake.top/api/packages/dsh-plugin/npm/@dsh-plugin%2Fsession-delete/-/1.0.2/session-delete-1.0.2.tgz) 下载到运行 DSH 的机器上,把它的绝对路径填进上面的输入框。
### 关于「npm 源」这条走不通的路
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@dsh-plugin/session-delete",
"version": "1.0.1",
"version": "1.0.2",
"description": "Permanently delete a conversation: stop it, remove its session log, subagent logs, and spilled tool output, and drop every registry reference. Settings → General can sweep orphaned temporary files left by conversations that are gone.",
"type": "module",
"license": "MIT",