Skip to content

Forward a Second Site's Token Pair to the Deploy-Site Verify Hook - #2173

Merged
ptr727 merged 1 commit into
developfrom
feature/2031-extra-site-verify
Sep 30, 2026
Merged

ptr727 merged 1 commit into
developfrom
feature/2031-extra-site-verify

Conversation

@ptr727

@ptr727 ptr727 commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Summary

A gate's access token opens only the resource it was issued for. A bundle that serves a second site on its own hostname, behind its own gate, cannot verify that site with the first site's pair. Every such request is redirected to the login page.

  • deploy-site-task.yml declares an optional SITE_EXTRA_AUTH_TOKEN_ID/SITE_EXTRA_AUTH_TOKEN secret pair.
  • The assert step checks the new pair both-or-neither, like the existing pair. It also refuses a mapped pair when the SITE_EXTRA_BASE_URL environment variable is empty, since then there is no site to check.
  • The new pair and SITE_EXTRA_BASE_URL are forwarded as env: to the verify invocation only. The build, prune, upload and flip steps never see them.
  • WORKFLOW.md and docs/reusable-workflows.md state the new handoff, and the tracker records it.

This is the first of the candidate shapes on #2031, as the maintainer decided there. Each caller maps its own secret names onto the new pair, and its verify hook reads them. Blog's side is Blog#272.

The added workflow comments follow the existing pattern for the first pair, hence the comments label.

Verification

actionlint, markdownlint, cspell, the prose gate over the merge-base diff, spec/validate.py, and the unittest suite all pass. A local strict review ran once, and its only finding was the comments label, which this PR carries.

Closes on promotion: #2031

🤖 Generated with Claude Code

A gate's access token opens only the resource it was issued for, so a
bundle serving a second site on its own hostname cannot verify it with
the first site's pair. deploy-site-task.yml now declares an optional
SITE_EXTRA_AUTH_TOKEN_ID/SITE_EXTRA_AUTH_TOKEN pair, asserts it
both-or-neither and against a non-empty SITE_EXTRA_BASE_URL variable,
and forwards all three to the verify invocation only, the shape decided
on #2031. WORKFLOW.md and docs/reusable-workflows.md state it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ptr727 ptr727 added the comments Permits the comment lines the pull request adds or edits, which the prose gate otherwise refuses label Sep 30, 2026
Copilot AI balanced review requested due to automatic review settings September 30, 2026 15:59
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: ptr727/ProjectTemplate/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: f2148d62-6271-40ad-b1f3-e66ab4e5ffba

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (develop@6adf0bf). Learn more about missing BASE report.

Additional details and impacted files
@@            Coverage Diff             @@
##             develop    #2173   +/-   ##
==========================================
  Coverage           ?   56.47%           
==========================================
  Files              ?       16           
  Lines              ?     7455           
  Branches           ?        0           
==========================================
  Hits               ?     4210           
  Misses             ?     3245           
  Partials           ?        0           
Flag Coverage Δ
python-3.13 56.47% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The change forwards deployment authentication secrets across a cross-repository reusable-workflow boundary, a security-sensitive CI/CD surface that warrants final human confirmation even though the additive logic mirrors the existing verified pattern and has no defects.

Review effort: Balanced
Findings: None

What changed in this PR

This PR extends the hub-hosted deploy-site-task.yml so a deploy bundle that serves a second token-gated site (on its own hostname behind its own proxy resource) can forward that site's credentials to the verify hook. A Pangolin resource access token is bound to one resource, so the first site's pair cannot authenticate the second; without this, every second-site verification request is redirected to the login page. The change realizes the first candidate shape decided in issue #2031: a generic optional extra pair plus a base-URL variable, forwarded as env: on the verify invocation only, with each caller mapping its own secret names onto these generic names.

Changes:

  • Declare optional SITE_EXTRA_AUTH_TOKEN_ID/SITE_EXTRA_AUTH_TOKEN secrets and assert them both-or-neither, additionally requiring a non-empty SITE_EXTRA_BASE_URL when the pair is mapped.
  • Forward SITE_EXTRA_BASE_URL and the extra pair as env: on the verify hook invocation only, leaving build/prune/upload/flip untouched.
  • Document the new handoff in WORKFLOW.md, docs/reusable-workflows.md, and its adoption tracker.
File Description
.github/​workflows/​deploy-site-task.yml Adds the optional second-site secret pair, its both-or-neither + base-URL assert, and env forwarding on the verify step only.
WORKFLOW.md Updates the hugo deploy contract prose to describe the extra pair and its SITE_EXTRA_BASE_URL requirement.
docs/​reusable-workflows.md Documents the second-site handoff in the Deploy-site section and adoption tracker, adding the issue-2031 reference link.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@ptr727

ptr727 commented Sep 30, 2026

Copy link
Copy Markdown
Owner Author

Merging without a CodeRabbit round, by the maintainer's decision on 2026-09-30. CodeRabbit's hourly review quota was already spent on #2169 and is reserved for #2172. What read this change: Copilot at head 913b8bf1 (full file-table coverage, no findings) and one local strict review pass.

@ptr727
ptr727 merged commit 1b061a0 into develop Sep 30, 2026
11 checks passed
@ptr727
ptr727 deleted the feature/2031-extra-site-verify branch September 30, 2026 16:05
ptr727 added a commit that referenced this pull request Sep 30, 2026
… a Second Site's Verify Token Pair, With Fifteen More (#2175)

## Summary

Promotes develop to main, carrying these pull requests:

- [#2172](#2172) Accept
Letters in Recorded Names in the Charset Rule and Prose Gate
- [#2173](#2173) Forward a
Second Site's Token Pair to the Deploy-Site Verify Hook
- [#2169](#2169) Record
HomeAutomation-Config's Merge-Bot and Gate Adoption in the Rollout
Tracking
- [#2164](#2164) Pass
--no-project to the Pre-Commit Snippet's uv run Hooks
- [#2161](#2161) Stop
Crediting an until read Loop as Bounded in the Guard
- [#2158](#2158) Drop the
Path Argument From the Pre-Commit Snippet's Mypy Swap
- [#2155](#2155) Reword
the Canonical CRLF-Exception Comments for a Carrier's Own Pin
- [#2153](#2153) End the
Guard's Stdin Redirect Scan at a Reserved Word
- [#2150](#2150) Describe
the Pip Form Consistently Across python-codestyle
- [#2144](#2144) Read the
Run Id From the Runner's Environment in the Artifact-Cleanup Steps
- [#2142](#2142) Diff a
Merge Commit's Prose Against Its Merged-In Parent in the Pre-Commit Hook
- [#2136](#2136) Qualify
the Local Review Skill's Merge-Base Command to Match the Engine
- [#2134](#2134) Quote the
Bare Placeholder in skills_install.py's Usage Block
- [#2132](#2132) Write the
Hub-Checkout Reach Into the session-handoff Chain Commands
- [#2130](#2130) Name the
Missing build-system Condition in the Lint-Only Profile Bullet
- [#2128](#2128) Skip a
Blockquoted List Marker in the Prose Gate's Semicolon Rule
- [#2119](#2119) State the
Three Gaps D4.7's Supersede-and-Dispatch Step Leaves Open

## Closes

Closes #2100
Closes #2031
Closes #1779
Closes #2148
Closes #1633
Closes #1188
Closes #1992
Closes #2032
Closes #2052
Closes #1481
Closes #2116
Closes #2107
Closes #2097
Closes #1512
Closes #2026
Closes #2101
Closes #2009

🤖 Generated with [Claude Code](https://claude.com/claude-code)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Deployment verification can now check a second site using its own
optional authentication token.
* **Documentation**
* Updated writing guidance to preserve the spelling and diacritics of
recorded names.
* Clarified Python project setup, formatting and testing guidance, and
line-ending rules.
* Expanded deployment and publishing guidance, including scenarios where
publishing runs overlap.
* **Bug Fixes**
* Prose checks now handle quoted lists and tables more accurately, and
merge checks avoid flagging comments brought in from the merged branch.
  * Improved checks for shell loops that read redirected input.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comments Permits the comment lines the pull request adds or edits, which the prose gate otherwise refuses

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants