probe: #205 workflow-token dispatch evidence (temporary branch)
All checks were successful
token dispatch probe / probe (push) Successful in 4s
All checks were successful
token dispatch probe / probe (push) Successful in 4s
Authorized in !213 #6254: one dispatch of release-exercise.yml under ${{ github.token }}, body {"ref":"main"} with no inputs, actions: write granted explicitly. Branch is deleted once the code is recorded on #205. Refs #205
This commit is contained in:
parent
94d5b81964
commit
c1fc2c06de
1 changed files with 42 additions and 0 deletions
42
.github/workflows/token-dispatch-probe.yml
vendored
Normal file
42
.github/workflows/token-dispatch-probe.yml
vendored
Normal file
|
|
@ -0,0 +1,42 @@
|
|||
# TEMPORARY PROBE — #205's workflow-token evidence, authorized by andres in
|
||||
# !213 #6254. Lives only on probe/205-token-dispatch; the branch is deleted
|
||||
# once the status code is recorded on #205.
|
||||
#
|
||||
# The one question: does a dispatch POST succeed under ${{ github.token }} on
|
||||
# this instance? Every prior measurement used a PAT, and the two identities
|
||||
# demonstrably differ here (#192: DELETE labels -> 500 for the workflow token,
|
||||
# 204 for a PAT). Target and terms per the authorization: release-exercise.yml
|
||||
# (dry wiring, doors push-gated so a dispatch skips them), body exactly
|
||||
# {"ref":"main"} with NO inputs — it declares none, and an input-contract
|
||||
# refusal would masquerade as a token failure.
|
||||
name: token dispatch probe
|
||||
on:
|
||||
push:
|
||||
branches: [probe/205-token-dispatch]
|
||||
|
||||
permissions:
|
||||
actions: write # the write under test, granted explicitly (#6254)
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
probe:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: dispatch release-exercise.yml as the workflow token
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ github.token }}
|
||||
run: |
|
||||
out="$(mktemp)"
|
||||
code="$(curl -sS -o "$out" -w '%{http_code}' -X POST \
|
||||
-H "Authorization: Bearer $GITHUB_TOKEN" \
|
||||
-H 'Content-Type: application/json' \
|
||||
-d '{"ref":"main"}' \
|
||||
"$GITHUB_API_URL/repos/$GITHUB_REPOSITORY/actions/workflows/release-exercise.yml/dispatches")"
|
||||
echo "probe: POST .../release-exercise.yml/dispatches as github.token -> HTTP $code"
|
||||
echo "probe: response body: $(tr -d '\n' <"$out")"
|
||||
if [ "$code" = "204" ]; then
|
||||
echo "probe: the workflow token CAN dispatch on this instance."
|
||||
else
|
||||
echo "probe: NON-204 under the workflow token — a finding in its own right (#205)."
|
||||
exit 1
|
||||
fi
|
||||
Loading…
Reference in a new issue