ci: make a repeated release a no-op and drop the misleading diagnostics

Gitea does not implement the npm whoami endpoint and npm refuses to read an auth token back, so both lines only produced error-looking output. The run now checks the registry first and skips publishing a version that already exists, which also makes a manual re-run safe.
This commit is contained in:
pyh
2026-09-30 11:28:57 +08:00
parent 733f0ba456
commit f4e107782a
2 changed files with 31 additions and 22 deletions
+28 -20
View File
@@ -2,24 +2,20 @@
#
# 触发方式:
# 1. 推送版本标签(推荐):git tag -a v1.0.1 -m "..." && git push origin v1.0.1
# 2. 仓库 → Actions → 选择本工作流 → Run workflow(手动,发布当前 commit 的版本)
# 2. 仓库 → Actions → 选择本工作流 → Run workflow(手动,发布当前 ref 的版本)
#
# 已发布的版本会自动跳过:手动重跑同一个版本不会失败,只是什么都不发。
#
# 需要的权限:
# 默认使用 Gitea 内置的任务令牌 ${{ secrets.GITEA_TOKEN }} 发布,无需额外配置密钥。
# 默认使用 Gitea 内置的任务令牌 ${{ secrets.GITEA_TOKEN }} 发布。
# 若实例/组织把 Actions 的令牌上限设为只读,或任务令牌对包命名空间没有写权限,
# 请在仓库 Settings → Actions → Secrets 里添加 NPM_TOKEN = 一个带 package 写权限的个人访问令牌,
# 工作流会自动优先使用它(见最后一个步骤)。
#
# 失败排查:
# 发布步骤在 1 秒内失败通常是鉴权问题——先看该步骤日志里 `npm whoami` 的输出:
# 打印出用户名说明令牌可用,报 E401/E403 说明令牌无效或权限不足。
# 就配置一个带 write:package 权限的个人访问令牌:
# 仓库(或组织)Settings → Actions → Secrets → NPM_TOKEN。工作流会自动优先使用它。
#
# 依赖前提:
# - 实例启用了 Actions,且注册了 act_runner(否则工作流只会排队)。
# - 实例启用了 Actions 并注册了 act_runner;runs-on 的标签要与 runner 一致。
# - runner 需要能拉取 actions/checkout 与 actions/setup-node(默认从 github.com 取)。
# 若 runner 在无外网环境,请在 app.ini 里设 actions.DEFAULT_ACTIONS_URL = self 并把这两个
# action 镜像到自己的实例上。
# - runs-on 的标签要与 runner 配置的标签一致(默认 ubuntu-latest;自建 runner 常用 docker/ubuntu-22.04 等)。
# - 包名、`cordis.patch.yml` 的 name、客户端模块 id 三处必须一致,改名时别漏。
name: publish
on:
@@ -48,7 +44,8 @@ jobs:
node-version: '22'
registry-url: https://gitea.iwake.top/api/packages/dsh-plugin/npm/
- name: Check the tag against package.json
- name: Read and check the version
id: version
run: |
set -eu
version="$(node -p "require('./package.json').version")"
@@ -62,15 +59,29 @@ jobs:
fi
;;
esac
echo "将发布 ${name}@${version}"
echo "name=${name}" >> "${GITHUB_OUTPUT}"
echo "version=${version}" >> "${GITHUB_OUTPUT}"
echo "目标:${name}@${version}"
- name: Pack (preview the published contents)
run: npm pack --dry-run
- name: Skip when this version is already published
id: published
run: |
set -eu
spec="${{ steps.version.outputs.name }}@${{ steps.version.outputs.version }}"
# 注册表里查得到就说明这个版本发布过了(Gitea 不允许同版本重复发布)。
if npm view "${spec}" version --registry "${REGISTRY}" > /dev/null 2>&1; then
echo "already=true" >> "${GITHUB_OUTPUT}"
echo "${spec} 已经发布过,本次跳过"
else
echo "already=false" >> "${GITHUB_OUTPUT}"
fi
- name: Publish
if: steps.published.outputs.already == 'false'
env:
# 优先使用带 package 写权限的 PAT(仓库 Settings → Actions → Secrets 里的 NPM_TOKEN);
# 没有配置时退回 Gitea 内置任务令牌 GITEA_TOKEN。
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
JOB_TOKEN: ${{ secrets.GITEA_TOKEN }}
run: |
@@ -81,11 +92,8 @@ jobs:
exit 1
fi
# 作用域与默认注册表都指向本组织的 npm 仓库,并把令牌写进本机 .npmrc。
# 注意:npm 不允许用 `npm config get` 读回 _authToken(会报 protected),所以不打印它。
npm config set @dsh-plugin:registry "${REGISTRY}"
npm config set "//gitea.iwake.top/api/packages/dsh-plugin/npm/:_authToken" "${token}"
echo "registry = $(npm config get registry)"
echo "auth = $(npm config get "//gitea.iwake.top/api/packages/dsh-plugin/npm/:_authToken" | sed 's/./*/g')"
# 鉴权自检:能取到用户就说明令牌对得上这个注册表(包不存在时报 404 也算通过)。
npm whoami --registry "${REGISTRY}" || true
npm publish --registry "${REGISTRY}" --access public