buildx(build): always register as secret the value passed as build secret string
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
This commit is contained in:
@@ -32,6 +32,11 @@ export interface BuildOpts {
|
|||||||
buildx?: Buildx;
|
buildx?: Buildx;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export interface ResolveSecretsOpts {
|
||||||
|
asFile?: boolean;
|
||||||
|
redact?: boolean;
|
||||||
|
}
|
||||||
|
|
||||||
export class Build {
|
export class Build {
|
||||||
private readonly buildx: Buildx;
|
private readonly buildx: Buildx;
|
||||||
private readonly iidFilename: string;
|
private readonly iidFilename: string;
|
||||||
@@ -124,12 +129,16 @@ export class Build {
|
|||||||
}
|
}
|
||||||
|
|
||||||
public static resolveSecretString(kvp: string): string {
|
public static resolveSecretString(kvp: string): string {
|
||||||
const [key, file] = Build.resolveSecret(kvp, false);
|
const [key, file] = Build.resolveSecret(kvp, {
|
||||||
|
redact: true
|
||||||
|
});
|
||||||
return `id=${key},src=${file}`;
|
return `id=${key},src=${file}`;
|
||||||
}
|
}
|
||||||
|
|
||||||
public static resolveSecretFile(kvp: string): string {
|
public static resolveSecretFile(kvp: string): string {
|
||||||
const [key, file] = Build.resolveSecret(kvp, true);
|
const [key, file] = Build.resolveSecret(kvp, {
|
||||||
|
asFile: true
|
||||||
|
});
|
||||||
return `id=${key},src=${file}`;
|
return `id=${key},src=${file}`;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -138,10 +147,10 @@ export class Build {
|
|||||||
return `id=${key},env=${value}`;
|
return `id=${key},env=${value}`;
|
||||||
}
|
}
|
||||||
|
|
||||||
public static resolveSecret(kvp: string, file: boolean): [string, string] {
|
public static resolveSecret(kvp: string, opts?: ResolveSecretsOpts): [string, string] {
|
||||||
const [key, value] = Build.parseSecretKvp(kvp);
|
const [key, value] = Build.parseSecretKvp(kvp, opts?.redact);
|
||||||
const secretFile = Context.tmpName({tmpdir: Context.tmpDir()});
|
const secretFile = Context.tmpName({tmpdir: Context.tmpDir()});
|
||||||
if (file) {
|
if (opts?.asFile) {
|
||||||
if (!fs.existsSync(value)) {
|
if (!fs.existsSync(value)) {
|
||||||
throw new Error(`secret file ${value} not found`);
|
throw new Error(`secret file ${value} not found`);
|
||||||
}
|
}
|
||||||
@@ -310,13 +319,16 @@ export class Build {
|
|||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
private static parseSecretKvp(kvp: string): [string, string] {
|
public static parseSecretKvp(kvp: string, redact?: boolean): [string, string] {
|
||||||
const delimiterIndex = kvp.indexOf('=');
|
const delimiterIndex = kvp.indexOf('=');
|
||||||
const key = kvp.substring(0, delimiterIndex);
|
const key = kvp.substring(0, delimiterIndex);
|
||||||
const value = kvp.substring(delimiterIndex + 1);
|
const value = kvp.substring(delimiterIndex + 1);
|
||||||
if (key.length == 0 || value.length == 0) {
|
if (key.length == 0 || value.length == 0) {
|
||||||
throw new Error(`${kvp} is not a valid secret`);
|
throw new Error(`${kvp} is not a valid secret`);
|
||||||
}
|
}
|
||||||
|
if (redact) {
|
||||||
|
core.setSecret(value);
|
||||||
|
}
|
||||||
return [key, value];
|
return [key, value];
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user