probe: #205 workflow-token dispatch evidence (temporary branch)
All checks were successful
token dispatch probe / probe (push) Successful in 4s

Authorized in !213 #6254: one dispatch of release-exercise.yml under
${{ github.token }}, body {"ref":"main"} with no inputs, actions: write
granted explicitly. Branch is deleted once the code is recorded on #205.

Refs #205
This commit is contained in:
clad2 2026-08-05 17:40:07 +00:00
parent 94d5b81964
commit c1fc2c06de

View file

@ -0,0 +1,42 @@
# TEMPORARY PROBE — #205's workflow-token evidence, authorized by andres in
# !213 #6254. Lives only on probe/205-token-dispatch; the branch is deleted
# once the status code is recorded on #205.
#
# The one question: does a dispatch POST succeed under ${{ github.token }} on
# this instance? Every prior measurement used a PAT, and the two identities
# demonstrably differ here (#192: DELETE labels -> 500 for the workflow token,
# 204 for a PAT). Target and terms per the authorization: release-exercise.yml
# (dry wiring, doors push-gated so a dispatch skips them), body exactly
# {"ref":"main"} with NO inputs — it declares none, and an input-contract
# refusal would masquerade as a token failure.
name: token dispatch probe
on:
push:
branches: [probe/205-token-dispatch]
permissions:
actions: write # the write under test, granted explicitly (#6254)
contents: read
jobs:
probe:
runs-on: ubuntu-latest
steps:
- name: dispatch release-exercise.yml as the workflow token
env:
GITHUB_TOKEN: ${{ github.token }}
run: |
out="$(mktemp)"
code="$(curl -sS -o "$out" -w '%{http_code}' -X POST \
-H "Authorization: Bearer $GITHUB_TOKEN" \
-H 'Content-Type: application/json' \
-d '{"ref":"main"}' \
"$GITHUB_API_URL/repos/$GITHUB_REPOSITORY/actions/workflows/release-exercise.yml/dispatches")"
echo "probe: POST .../release-exercise.yml/dispatches as github.token -> HTTP $code"
echo "probe: response body: $(tr -d '\n' <"$out")"
if [ "$code" = "204" ]; then
echo "probe: the workflow token CAN dispatch on this instance."
else
echo "probe: NON-204 under the workflow token — a finding in its own right (#205)."
exit 1
fi