From 8c3680d880b5b56b76b84adb475e12ac395eae42 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Mon, 21 Sep 2026 22:05:17 -0300 Subject: [PATCH 1/2] fix: use configured app secrets in consumer workflows Signed-off-by: Vitor Mattos --- tests/test_portable_workflow_sync_auth.py | 7 +++++++ tests/test_prepare_release_template.py | 15 +++++++++++---- workflow-templates/prepare-release.yml | 10 +++++----- workflow-templates/sync-workflow-templates.yml | 4 ++-- 4 files changed, 25 insertions(+), 11 deletions(-) diff --git a/tests/test_portable_workflow_sync_auth.py b/tests/test_portable_workflow_sync_auth.py index a22ddfd..2b34760 100644 --- a/tests/test_portable_workflow_sync_auth.py +++ b/tests/test_portable_workflow_sync_auth.py @@ -29,6 +29,13 @@ def test_external_modes_do_not_require_librecode_credentials(self) -> None: self.assertIn('github-app) token="${CONSUMER_APP_TOKEN}"', content) self.assertIn('token) token="${CONSUMER_TOKEN}"', content) + def test_librecode_app_credentials_use_actions_secrets(self) -> None: + content = TEMPLATE.read_text(encoding="utf-8") + + self.assertIn("LIBRECODE_APP_ID: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}", content) + self.assertIn("app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}", content) + self.assertNotIn("vars.LIBRECODE_WORKFLOW_APP_ID", content) + def test_generated_pull_request_uses_selected_token(self) -> None: content = TEMPLATE.read_text(encoding="utf-8") diff --git a/tests/test_prepare_release_template.py b/tests/test_prepare_release_template.py index 7f185fb..9538dbe 100644 --- a/tests/test_prepare_release_template.py +++ b/tests/test_prepare_release_template.py @@ -43,21 +43,28 @@ def test_dispatch_help_is_concise_and_explains_risky_inputs(self) -> None: def test_template_delegates_all_release_stages_to_versioned_actions(self) -> None: content = TEMPLATE.read_text(encoding="utf-8") - sha = "622599cc128ec55007b443d2908f78da930b8a21" + sha = "5a16fb0ae5b846117f70e1d86a1d25e46492c333" self.assertIn( - f"actions/release-prepare@{sha} # v0.5.0", + f"actions/release-prepare@{sha} # v0.6.2", content, ) self.assertIn( - f"actions/release-post-merge@{sha} # v0.5.0", + f"actions/release-post-merge@{sha} # v0.6.2", content, ) self.assertIn( - f"actions/release-publication@{sha} # v0.5.0", + f"actions/release-publication@{sha} # v0.6.2", content, ) + def test_release_mutation_credentials_use_actions_secrets(self) -> None: + content = TEMPLATE.read_text(encoding="utf-8") + + self.assertEqual(2, content.count("secrets.LIBRECODE_WORKFLOW_APP_ID")) + self.assertEqual(2, content.count("secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY")) + self.assertNotIn("vars.LIBRECODE_WORKFLOW_APP_ID", content) + def test_template_keeps_permissions_stage_scoped(self) -> None: content = TEMPLATE.read_text(encoding="utf-8") diff --git a/workflow-templates/prepare-release.yml b/workflow-templates/prepare-release.yml index 8ccd851..e2aa36a 100644 --- a/workflow-templates/prepare-release.yml +++ b/workflow-templates/prepare-release.yml @@ -80,7 +80,7 @@ jobs: ref: ${{ inputs.ref != '' && inputs.ref || inputs.branch }} - name: Prepare release - uses: LibreCodeCoop/github-workflows/actions/release-prepare@622599cc128ec55007b443d2908f78da930b8a21 # v0.5.0 + uses: LibreCodeCoop/github-workflows/actions/release-prepare@5a16fb0ae5b846117f70e1d86a1d25e46492c333 # v0.6.2 with: branch: ${{ inputs.branch }} ref: ${{ inputs.ref }} @@ -93,7 +93,7 @@ jobs: config-path: .nextcloud-release.yml actor: ${{ github.actor }} github-token: ${{ secrets.GITHUB_TOKEN }} - app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }} app-private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} post_merge: @@ -118,14 +118,14 @@ jobs: ref: ${{ github.event.pull_request.base.ref }} - name: Finalize merged release - uses: LibreCodeCoop/github-workflows/actions/release-post-merge@622599cc128ec55007b443d2908f78da930b8a21 # v0.5.0 + uses: LibreCodeCoop/github-workflows/actions/release-post-merge@5a16fb0ae5b846117f70e1d86a1d25e46492c333 # v0.6.2 with: pull-request-number: ${{ github.event.pull_request.number }} merger: ${{ github.event.pull_request.merged_by.login }} config-path: .nextcloud-release.yml prepare-workflow-path: .github/workflows/prepare-release.yml github-token: ${{ secrets.GITHUB_TOKEN }} - app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }} app-private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} verify_publication: @@ -145,7 +145,7 @@ jobs: ref: ${{ github.event.release.tag_name }} - name: Verify publication - uses: LibreCodeCoop/github-workflows/actions/release-publication@622599cc128ec55007b443d2908f78da930b8a21 # v0.5.0 + uses: LibreCodeCoop/github-workflows/actions/release-publication@5a16fb0ae5b846117f70e1d86a1d25e46492c333 # v0.6.2 with: github-release-id: ${{ github.event.release.id }} config-path: .nextcloud-release.yml diff --git a/workflow-templates/sync-workflow-templates.yml b/workflow-templates/sync-workflow-templates.yml index a0e59f2..8302ce5 100644 --- a/workflow-templates/sync-workflow-templates.yml +++ b/workflow-templates/sync-workflow-templates.yml @@ -46,7 +46,7 @@ jobs: shell: bash env: AUTH_MODE: ${{ vars.WORKFLOW_SYNC_AUTH_MODE || 'librecode-app' }} - LIBRECODE_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + LIBRECODE_APP_ID: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }} LIBRECODE_APP_PRIVATE_KEY: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} CONSUMER_APP_ID: ${{ vars.WORKFLOW_SYNC_APP_ID }} CONSUMER_APP_PRIVATE_KEY: ${{ secrets.WORKFLOW_SYNC_APP_PRIVATE_KEY }} @@ -86,7 +86,7 @@ jobs: id: librecode-app-token uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 with: - app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }} private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} owner: ${{ github.repository_owner }} repositories: ${{ github.event.repository.name }} From 2f4429975b1abf37f458ef7ce9e50d25b18ec3cd Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Mon, 21 Sep 2026 22:06:07 -0300 Subject: [PATCH 2/2] fix: keep sync workflow generated from patch Signed-off-by: Vitor Mattos --- patches/nextcloud/sync-workflow-templates.yml.patch | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/patches/nextcloud/sync-workflow-templates.yml.patch b/patches/nextcloud/sync-workflow-templates.yml.patch index 076776a..64ff318 100644 --- a/patches/nextcloud/sync-workflow-templates.yml.patch +++ b/patches/nextcloud/sync-workflow-templates.yml.patch @@ -38,7 +38,7 @@ + shell: bash + env: + AUTH_MODE: ${{ vars.WORKFLOW_SYNC_AUTH_MODE || 'librecode-app' }} -+ LIBRECODE_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} ++ LIBRECODE_APP_ID: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }} + LIBRECODE_APP_PRIVATE_KEY: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} + CONSUMER_APP_ID: ${{ vars.WORKFLOW_SYNC_APP_ID }} + CONSUMER_APP_PRIVATE_KEY: ${{ secrets.WORKFLOW_SYNC_APP_PRIVATE_KEY }} @@ -78,7 +78,7 @@ + id: librecode-app-token + uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 + with: -+ app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} ++ app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }} + private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} + owner: ${{ github.repository_owner }} + repositories: ${{ github.event.repository.name }}