authexec

package
v8.114.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: Apache-2.0 Imports: 15 Imported by: 0

Documentation

Overview

Package authexec runs another program with the App login's GitHub token in its environment: `devctl auth exec`, and devctl started under a proxied name (a `gh` link to devctl), which runs the next `gh` on PATH so. The token reaches the program's environment only; devctl never prints it.

Index

Constants

View Source
const (
	// IdentityApp is the devctl GitHub App login.
	IdentityApp = "app"
	// IdentityGH is the person's own gh login.
	IdentityGH = "gh"
)

The identities a command's document names (Identity).

View Source
const EnvToken = "GH_TOKEN"

EnvToken is the variable the program finds the token in: gh's own, which it prefers over its stored login.

View Source
const MinValidity = 10 * time.Minute

MinValidity is how long the token stays valid at least when the program starts: a stored token that expires sooner is refreshed first, so a command started on it does not see it expire.

View Source
const SourceGHLogin = "gh login"

SourceGHLogin is authstore.Token.Source of the person's own gh login.

Variables

View Source
var AppOwners = map[string]bool{"giantswarm": true}

AppOwners are the accounts the giantswarm-devctl App is installed on: gh acts with the App token for their repositories and wherever no repository is named. A repository of another owner is out of the App's reach, so gh keeps the person's own login for it.

Functions

func Environ

func Environ(environ []string, token string) []string

Environ is environ with EnvToken set to token, any earlier value of it replaced.

func GHOwner

func GHOwner(args []string, environ []string, remotes func() string) string

GHOwner is the owner of the repository a gh invocation acts on, "" when it names none: --repo/-R, $GH_REPO, a repository path of `gh api`, the URL or repository argument of a repository command, else the repository of the working directory, resolved like gh (its default, then the remotes upstream, github and origin). remotes reads the working directory's remote configuration; nil reads none.

func Identity added in v8.114.0

func Identity(token authstore.Token) string

Identity names the identity token acts as in a command's document.

func LookPath

func LookPath(name, path, self string) (string, error)

LookPath is the program name names: a path as given, a bare name the first executable of that name on path that is not self (devctl, also through a link), so a `gh` link to devctl first on PATH runs the real gh.

func NotFoundHint added in v8.114.0

func NotFoundHint(token authstore.Token, owner string) string

NotFoundHint is the sentence a command acting through RepositoryToken adds to GitHub's 404: what the identity it used reaches and what is missing.

func PersonGitHub added in v8.114.0

func PersonGitHub(ctx context.Context) (authstore.Token, error)

PersonGitHub is the token of the person's own gh login: `gh auth token` of the real gh, never a gh link to devctl, and with neither $GH_TOKEN nor $GITHUB_TOKEN in its environment, so gh answers its stored login. No gh or no login is exit 8 naming `gh auth login`.

func Proxy

func Proxy(argv0 string) string

Proxy is the program devctl runs for the name it was started as (argv[0]), "" when that name is devctl's own.

func RepositoryToken added in v8.114.0

func RepositoryToken(ctx context.Context, owner string, app, person func(context.Context) (authstore.Token, error)) (authstore.Token, error)

RepositoryToken is the GitHub token a command acts with on owner's repositories: the App login (app) for an owner in AppOwners, where the App is installed, and the person's own gh login (person) for every other owner, which the App cannot reach.

func Run

func Run(ctx context.Context, c Config, name string, args []string) int

Run runs name with args and the token in EnvToken and returns the exit code to leave with: the program's, or 8 without a usable login and 7 when the program is not found, each with one line on stderr naming the cause. gh acting on a repository of an owner outside AppOwners runs without the token, on the person's own gh login.

Types

type Config

type Config struct {
	// Token returns the GitHub token valid for at least the duration.
	Token func(ctx context.Context, valid time.Duration) (authstore.Token, error)
	// Self is devctl's own executable, skipped on PATH so a proxy never
	// runs itself.
	Self string
	// Path and Environ are the process's PATH and environment.
	Path    string
	Environ []string
	// Remotes is the working directory's git remote configuration, which
	// names the repository a gh invocation without --repo acts on.
	Remotes func() string
	Stderr  io.Writer
	// Exec replaces the process with the program (or runs it and returns
	// its exit code where the platform cannot replace a process).
	Exec func(path string, argv, env []string) (int, error)
}

Config is what Run needs from its process; Default fills it in.

func Default

func Default() Config

Default is the Config of this process.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL