Repository navigation
Forward a Second Site's Token Pair to the Deploy-Site Verify Hook - #2173
Conversation
A gate's access token opens only the resource it was issued for, so a bundle serving a second site on its own hostname cannot verify it with the first site's pair. deploy-site-task.yml now declares an optional SITE_EXTRA_AUTH_TOKEN_ID/SITE_EXTRA_AUTH_TOKEN pair, asserts it both-or-neither and against a non-empty SITE_EXTRA_BASE_URL variable, and forwards all three to the verify invocation only, the shape decided on #2031. WORKFLOW.md and docs/reusable-workflows.md state it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Repository: ptr727/ProjectTemplate/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #2173 +/- ##
==========================================
Coverage ? 56.47%
==========================================
Files ? 16
Lines ? 7455
Branches ? 0
==========================================
Hits ? 4210
Misses ? 3245
Partials ? 0
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The change forwards deployment authentication secrets across a cross-repository reusable-workflow boundary, a security-sensitive CI/CD surface that warrants final human confirmation even though the additive logic mirrors the existing verified pattern and has no defects.
Review effort: Balanced
Findings: None
What changed in this PR
This PR extends the hub-hosted deploy-site-task.yml so a deploy bundle that serves a second token-gated site (on its own hostname behind its own proxy resource) can forward that site's credentials to the verify hook. A Pangolin resource access token is bound to one resource, so the first site's pair cannot authenticate the second; without this, every second-site verification request is redirected to the login page. The change realizes the first candidate shape decided in issue #2031: a generic optional extra pair plus a base-URL variable, forwarded as env: on the verify invocation only, with each caller mapping its own secret names onto these generic names.
Changes:
- Declare optional
SITE_EXTRA_AUTH_TOKEN_ID/SITE_EXTRA_AUTH_TOKENsecrets and assert them both-or-neither, additionally requiring a non-emptySITE_EXTRA_BASE_URLwhen the pair is mapped. - Forward
SITE_EXTRA_BASE_URLand the extra pair asenv:on theverifyhook invocation only, leaving build/prune/upload/flip untouched. - Document the new handoff in
WORKFLOW.md,docs/reusable-workflows.md, and its adoption tracker.
| File | Description |
|---|---|
.github/workflows/deploy-site-task.yml |
Adds the optional second-site secret pair, its both-or-neither + base-URL assert, and env forwarding on the verify step only. |
WORKFLOW.md |
Updates the hugo deploy contract prose to describe the extra pair and its SITE_EXTRA_BASE_URL requirement. |
docs/reusable-workflows.md |
Documents the second-site handoff in the Deploy-site section and adoption tracker, adding the issue-2031 reference link. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
… a Second Site's Verify Token Pair, With Fifteen More (#2175) ## Summary Promotes develop to main, carrying these pull requests: - [#2172](#2172) Accept Letters in Recorded Names in the Charset Rule and Prose Gate - [#2173](#2173) Forward a Second Site's Token Pair to the Deploy-Site Verify Hook - [#2169](#2169) Record HomeAutomation-Config's Merge-Bot and Gate Adoption in the Rollout Tracking - [#2164](#2164) Pass --no-project to the Pre-Commit Snippet's uv run Hooks - [#2161](#2161) Stop Crediting an until read Loop as Bounded in the Guard - [#2158](#2158) Drop the Path Argument From the Pre-Commit Snippet's Mypy Swap - [#2155](#2155) Reword the Canonical CRLF-Exception Comments for a Carrier's Own Pin - [#2153](#2153) End the Guard's Stdin Redirect Scan at a Reserved Word - [#2150](#2150) Describe the Pip Form Consistently Across python-codestyle - [#2144](#2144) Read the Run Id From the Runner's Environment in the Artifact-Cleanup Steps - [#2142](#2142) Diff a Merge Commit's Prose Against Its Merged-In Parent in the Pre-Commit Hook - [#2136](#2136) Qualify the Local Review Skill's Merge-Base Command to Match the Engine - [#2134](#2134) Quote the Bare Placeholder in skills_install.py's Usage Block - [#2132](#2132) Write the Hub-Checkout Reach Into the session-handoff Chain Commands - [#2130](#2130) Name the Missing build-system Condition in the Lint-Only Profile Bullet - [#2128](#2128) Skip a Blockquoted List Marker in the Prose Gate's Semicolon Rule - [#2119](#2119) State the Three Gaps D4.7's Supersede-and-Dispatch Step Leaves Open ## Closes Closes #2100 Closes #2031 Closes #1779 Closes #2148 Closes #1633 Closes #1188 Closes #1992 Closes #2032 Closes #2052 Closes #1481 Closes #2116 Closes #2107 Closes #2097 Closes #1512 Closes #2026 Closes #2101 Closes #2009 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Deployment verification can now check a second site using its own optional authentication token. * **Documentation** * Updated writing guidance to preserve the spelling and diacritics of recorded names. * Clarified Python project setup, formatting and testing guidance, and line-ending rules. * Expanded deployment and publishing guidance, including scenarios where publishing runs overlap. * **Bug Fixes** * Prose checks now handle quoted lists and tables more accurately, and merge checks avoid flagging comments brought in from the merged branch. * Improved checks for shell loops that read redirected input. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Summary
A gate's access token opens only the resource it was issued for. A bundle that serves a second site on its own hostname, behind its own gate, cannot verify that site with the first site's pair. Every such request is redirected to the login page.
deploy-site-task.ymldeclares an optionalSITE_EXTRA_AUTH_TOKEN_ID/SITE_EXTRA_AUTH_TOKENsecret pair.SITE_EXTRA_BASE_URLenvironment variable is empty, since then there is no site to check.SITE_EXTRA_BASE_URLare forwarded asenv:to theverifyinvocation only. The build, prune, upload and flip steps never see them.WORKFLOW.mdanddocs/reusable-workflows.mdstate the new handoff, and the tracker records it.This is the first of the candidate shapes on #2031, as the maintainer decided there. Each caller maps its own secret names onto the new pair, and its verify hook reads them. Blog's side is Blog#272.
The added workflow comments follow the existing pattern for the first pair, hence the
commentslabel.Verification
actionlint, markdownlint, cspell, the prose gate over the merge-base diff,
spec/validate.py, and the unittest suite all pass. A local strict review ran once, and its only finding was thecommentslabel, which this PR carries.Closes on promotion: #2031
🤖 Generated with Claude Code