Merge pull request #115 from github/joshmgross/org-values

Support shared organization secrets and variables
This commit is contained in:
Josh Gross
2023-01-31 16:38:06 -05:00
committed by GitHub
2 changed files with 69 additions and 2 deletions
@@ -41,6 +41,15 @@ export async function getSecrets(
} }
>(); >();
secrets.orgSecrets.forEach(secret =>
secretsMap.set(secret.value.toLowerCase(), {
key: secret.value,
value: new data.StringData("***"),
description: "Organization secret"
})
);
// Override org secrets with repo secrets
secrets.repoSecrets.forEach(secret => secrets.repoSecrets.forEach(secret =>
secretsMap.set(secret.value.toLowerCase(), { secretsMap.set(secret.value.toLowerCase(), {
key: secret.value, key: secret.value,
@@ -76,6 +85,7 @@ async function getRemoteSecrets(
): Promise<{ ): Promise<{
repoSecrets: StringData[]; repoSecrets: StringData[];
environmentSecrets: StringData[]; environmentSecrets: StringData[];
orgSecrets: StringData[];
}> { }> {
return { return {
repoSecrets: await cache.get(`${repo.owner}/${repo.name}/secrets`, undefined, () => repoSecrets: await cache.get(`${repo.owner}/${repo.name}/secrets`, undefined, () =>
@@ -86,7 +96,8 @@ async function getRemoteSecrets(
(await cache.get(`${repo.owner}/${repo.name}/secrets/environment/${environmentName}`, undefined, () => (await cache.get(`${repo.owner}/${repo.name}/secrets/environment/${environmentName}`, undefined, () =>
fetchEnvironmentSecrets(octokit, repo.id, environmentName) fetchEnvironmentSecrets(octokit, repo.id, environmentName)
))) || ))) ||
[] [],
orgSecrets: await cache.get(`${repo.owner}/secrets`, undefined, () => fetchOrganizationSecrets(octokit, repo))
}; };
} }
@@ -129,3 +140,22 @@ async function fetchEnvironmentSecrets(
return []; return [];
} }
async function fetchOrganizationSecrets(octokit: Octokit, repo: RepositoryContext): Promise<StringData[]> {
if (!repo.organizationOwned) {
return [];
}
try {
const secrets: {name: string}[] = await octokit.paginate("GET /repos/{owner}/{repo}/actions/organization-secrets", {
owner: repo.owner,
repo: repo.name,
per_page: 100
});
return secrets.map(secret => new StringData(secret.name));
} catch (e) {
console.log("Failure to retrieve organization secrets: ", e);
}
return [];
}
@@ -42,6 +42,15 @@ export async function getVariables(
} }
>(); >();
variables.organizationVariables.forEach(variable =>
variablesMap.set(variable.key.toLowerCase(), {
key: variable.key,
value: new data.StringData(variable.value.coerceString()),
description: `${variable.value.coerceString()} - Organization variable`
})
);
// Override org variables with repo variables
variables.repoVariables.forEach(variable => variables.repoVariables.forEach(variable =>
variablesMap.set(variable.key.toLowerCase(), { variablesMap.set(variable.key.toLowerCase(), {
key: variable.key, key: variable.key,
@@ -77,6 +86,7 @@ export async function getRemoteVariables(
): Promise<{ ): Promise<{
repoVariables: Pair[]; repoVariables: Pair[];
environmentVariables: Pair[]; environmentVariables: Pair[];
organizationVariables: Pair[];
}> { }> {
// Repo variables // Repo variables
return { return {
@@ -88,7 +98,10 @@ export async function getRemoteVariables(
(await cache.get(`${repo.owner}/${repo.name}/vars/environment/${environmentName}`, undefined, () => (await cache.get(`${repo.owner}/${repo.name}/vars/environment/${environmentName}`, undefined, () =>
fetchEnvironmentVariables(octokit, repo.id, environmentName) fetchEnvironmentVariables(octokit, repo.id, environmentName)
))) || ))) ||
[] [],
organizationVariables: await cache.get(`${repo.owner}/vars`, undefined, () =>
fetchOrganizationVariables(octokit, repo)
)
}; };
} }
@@ -137,3 +150,27 @@ async function fetchEnvironmentVariables(
return []; return [];
} }
async function fetchOrganizationVariables(octokit: Octokit, repo: RepositoryContext): Promise<Pair[]> {
if (!repo.organizationOwned) {
return [];
}
try {
const variables: {name: string; value: string}[] = await octokit.paginate(
"GET /repos/{owner}/{repo}/actions/organization-variables",
{
owner: repo.owner,
repo: repo.name,
per_page: 100
}
);
return variables.map(variable => {
return {key: variable.name, value: new StringData(variable.value)};
});
} catch (e) {
console.log("Failure to retrieve organization variables: ", e);
}
return [];
}