Documentation
¶
Overview ¶
Package authexec runs another program with the App login's GitHub token in its environment: `devctl auth exec`, and devctl started under a proxied name (a `gh` link to devctl), which runs the next `gh` on PATH so. The token reaches the program's environment only; devctl never prints it.
Index ¶
- Constants
- Variables
- func Environ(environ []string, token string) []string
- func GHOwner(args []string, environ []string, remotes func() string) string
- func Identity(token authstore.Token) string
- func LookPath(name, path, self string) (string, error)
- func NotFoundHint(token authstore.Token, owner string) string
- func PersonGitHub(ctx context.Context) (authstore.Token, error)
- func Proxy(argv0 string) string
- func RepositoryToken(ctx context.Context, owner string, ...) (authstore.Token, error)
- func Run(ctx context.Context, c Config, name string, args []string) int
- type Config
Constants ¶
const ( // IdentityApp is the devctl GitHub App login. IdentityApp = "app" // IdentityGH is the person's own gh login. IdentityGH = "gh" )
The identities a command's document names (Identity).
const EnvToken = "GH_TOKEN"
EnvToken is the variable the program finds the token in: gh's own, which it prefers over its stored login.
const MinValidity = 10 * time.Minute
MinValidity is how long the token stays valid at least when the program starts: a stored token that expires sooner is refreshed first, so a command started on it does not see it expire.
const SourceGHLogin = "gh login"
SourceGHLogin is authstore.Token.Source of the person's own gh login.
Variables ¶
var AppOwners = map[string]bool{"giantswarm": true}
AppOwners are the accounts the giantswarm-devctl App is installed on: gh acts with the App token for their repositories and wherever no repository is named. A repository of another owner is out of the App's reach, so gh keeps the person's own login for it.
Functions ¶
func GHOwner ¶
GHOwner is the owner of the repository a gh invocation acts on, "" when it names none: --repo/-R, $GH_REPO, a repository path of `gh api`, the URL or repository argument of a repository command, else the repository of the working directory, resolved like gh (its default, then the remotes upstream, github and origin). remotes reads the working directory's remote configuration; nil reads none.
func Identity ¶ added in v8.114.0
Identity names the identity token acts as in a command's document.
func LookPath ¶
LookPath is the program name names: a path as given, a bare name the first executable of that name on path that is not self (devctl, also through a link), so a `gh` link to devctl first on PATH runs the real gh.
func NotFoundHint ¶ added in v8.114.0
NotFoundHint is the sentence a command acting through RepositoryToken adds to GitHub's 404: what the identity it used reaches and what is missing.
func PersonGitHub ¶ added in v8.114.0
PersonGitHub is the token of the person's own gh login: `gh auth token` of the real gh, never a gh link to devctl, and with neither $GH_TOKEN nor $GITHUB_TOKEN in its environment, so gh answers its stored login. No gh or no login is exit 8 naming `gh auth login`.
func Proxy ¶
Proxy is the program devctl runs for the name it was started as (argv[0]), "" when that name is devctl's own.
func RepositoryToken ¶ added in v8.114.0
func RepositoryToken(ctx context.Context, owner string, app, person func(context.Context) (authstore.Token, error)) (authstore.Token, error)
RepositoryToken is the GitHub token a command acts with on owner's repositories: the App login (app) for an owner in AppOwners, where the App is installed, and the person's own gh login (person) for every other owner, which the App cannot reach.
func Run ¶
Run runs name with args and the token in EnvToken and returns the exit code to leave with: the program's, or 8 without a usable login and 7 when the program is not found, each with one line on stderr naming the cause. gh acting on a repository of an owner outside AppOwners runs without the token, on the person's own gh login.
Types ¶
type Config ¶
type Config struct {
// Token returns the GitHub token valid for at least the duration.
Token func(ctx context.Context, valid time.Duration) (authstore.Token, error)
// Self is devctl's own executable, skipped on PATH so a proxy never
// runs itself.
Self string
// Path and Environ are the process's PATH and environment.
Path string
Environ []string
// Remotes is the working directory's git remote configuration, which
// names the repository a gh invocation without --repo acts on.
Remotes func() string
Stderr io.Writer
// Exec replaces the process with the program (or runs it and returns
// its exit code where the platform cannot replace a process).
Exec func(path string, argv, env []string) (int, error)
}
Config is what Run needs from its process; Default fills it in.