release: 1.0.2, and learn whether the built-in job token can publish
publish / npm (push) Successful in 5s
publish / npm (push) Successful in 5s
The publish step now tries the built-in Gitea job token first, prints which user it belongs to, falls back to NPM_TOKEN when the registry rejects it, and reports which token actually published. A 409 keeps meaning 'already published', so a re-run stays harmless.
This commit is contained in:
@@ -88,32 +88,65 @@ jobs:
|
||||
JOB_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||
run: |
|
||||
set -eu
|
||||
token="${NPM_TOKEN:-$JOB_TOKEN}"
|
||||
if [ -z "$token" ]; then
|
||||
echo "没有可用的发布令牌:请配置 NPM_TOKEN,或确认实例会注入 GITEA_TOKEN" >&2
|
||||
exit 1
|
||||
fi
|
||||
# 作用域与默认注册表都指向本组织的 npm 仓库(默认注册表也要设,否则 npm 会拿
|
||||
# registry.npmjs.org 的 packument 做“是否已发布”判断,甚至可能发错地方),
|
||||
# 并把令牌写进本机 .npmrc。
|
||||
# registry.npmjs.org 的 packument 做“是否已发布”判断,甚至可能发错地方)。
|
||||
# 注意:npm 不允许用 `npm config get` 读回 _authToken(会报 protected),所以不打印它。
|
||||
npm config set registry "${REGISTRY}"
|
||||
npm config set @dsh-plugin:registry "${REGISTRY}"
|
||||
npm config set "//gitea.iwake.top/api/packages/dsh-plugin/npm/:_authToken" "${token}"
|
||||
echo "registry = $(npm config get registry)"
|
||||
|
||||
# 已发布的版本由注册表自己判定:Gitea 对同版本返回 409(package version already
|
||||
# exists),npm 客户端在本地也会用 "cannot publish over the previously published
|
||||
# versions" 拦下来。两种都算“本次无需发布”而不是失败;其余错误(E401/E403 等)照旧失败。
|
||||
set +e
|
||||
output="$(npm publish --registry "${REGISTRY}" --access public 2>&1)"
|
||||
status=$?
|
||||
set -e
|
||||
printf '%s\n' "${output}"
|
||||
if [ "${status}" -eq 0 ]; then
|
||||
echo "已发布 ${{ steps.version.outputs.name }}@${{ steps.version.outputs.version }}"
|
||||
elif printf '%s' "${output}" | grep -Eqi 'E409|already exists|previously published|cannot publish over'; then
|
||||
echo "${{ steps.version.outputs.name }}@${{ steps.version.outputs.version }} 已存在,本次跳过(不算失败)"
|
||||
# 内置任务令牌到底是谁、能不能写这个包命名空间:先打印身份,便于事后判断。
|
||||
if [ -n "${JOB_TOKEN:-}" ]; then
|
||||
server="${GITHUB_SERVER_URL:-https://gitea.iwake.top}"
|
||||
who="$(curl -fsS -H "Authorization: token ${JOB_TOKEN}" "${server}/api/v1/user" 2>/dev/null | head -c 300 || true)"
|
||||
echo "内置任务令牌身份:${who:-(查询失败,可能是 curl 不可用或令牌被拒)}"
|
||||
else
|
||||
exit "${status}"
|
||||
echo "实例没有注入内置任务令牌(secrets.GITEA_TOKEN 为空)"
|
||||
fi
|
||||
|
||||
RESULT=""
|
||||
# 结果分类:published 成功 / exists 版本已存在(不视为失败)/ auth 令牌被拒 / error 其他
|
||||
run_publish() {
|
||||
label="$1"
|
||||
token="$2"
|
||||
LAST_LABEL="${label}"
|
||||
echo "--- 用 ${label} 发布 ---"
|
||||
npm config set "//gitea.iwake.top/api/packages/dsh-plugin/npm/:_authToken" "${token}"
|
||||
set +e
|
||||
output="$(npm publish --registry "${REGISTRY}" --access public 2>&1)"
|
||||
status=$?
|
||||
set -e
|
||||
printf '%s\n' "${output}"
|
||||
if [ "${status}" -eq 0 ]; then RESULT="published"; return 0; fi
|
||||
if printf '%s' "${output}" | grep -Eqi 'E409|already exists|previously published|cannot publish over'; then RESULT="exists"; return 0; fi
|
||||
if printf '%s' "${output}" | grep -Eqi 'E401|E403|EOTP|unauthorized|forbidden'; then RESULT="auth"; return 0; fi
|
||||
RESULT="error"
|
||||
return 1
|
||||
}
|
||||
|
||||
if [ -n "${JOB_TOKEN:-}" ]; then
|
||||
run_publish "内置任务令牌 GITEA_TOKEN" "${JOB_TOKEN}"
|
||||
fi
|
||||
if [ "${RESULT}" = "auth" ]; then
|
||||
echo "内置任务令牌无法发布这个包(见上面的错误码),改用 NPM_TOKEN 重试"
|
||||
RESULT=""
|
||||
if [ -n "${NPM_TOKEN:-}" ]; then
|
||||
run_publish "个人访问令牌 NPM_TOKEN" "${NPM_TOKEN}"
|
||||
else
|
||||
echo "没有配置 NPM_TOKEN,无处回退" >&2
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
case "${RESULT}" in
|
||||
published)
|
||||
echo "已发布 ${{ steps.version.outputs.name }}@${{ steps.version.outputs.version }}(本次用的是 ${LAST_LABEL:-令牌})"
|
||||
;;
|
||||
exists)
|
||||
echo "${{ steps.version.outputs.name }}@${{ steps.version.outputs.version }} 已存在,本次跳过(不算失败)"
|
||||
;;
|
||||
*)
|
||||
echo "发布失败" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
Reference in New Issue
Block a user