fix(08-fix): WR-05 bind REGISTRY_PAT via env: and pipe with printf for docker login
This commit is contained in:
@@ -59,8 +59,15 @@ jobs:
|
|||||||
# Secret is named REGISTRY_PAT (not GITEA_REGISTRY_PAT): Gitea reserves the GITEA_ prefix
|
# Secret is named REGISTRY_PAT (not GITEA_REGISTRY_PAT): Gitea reserves the GITEA_ prefix
|
||||||
# for secret names, so the GITEA_-prefixed name cannot be created.
|
# for secret names, so the GITEA_-prefixed name cannot be created.
|
||||||
- name: Docker login
|
- name: Docker login
|
||||||
|
# Bind the secret through env: so it is never substituted into the rendered
|
||||||
|
# script body. Read it as $REGISTRY_PAT and pipe with printf '%s' (echo is not
|
||||||
|
# safe for arbitrary strings — a trailing newline or shell-significant char
|
||||||
|
# would mangle the password into a confusing `unauthorized`) (WR-05).
|
||||||
|
env:
|
||||||
|
REGISTRY_PAT: ${{ secrets.REGISTRY_PAT }}
|
||||||
run: |
|
run: |
|
||||||
echo "${{ secrets.REGISTRY_PAT }}" | \
|
set -euo pipefail
|
||||||
|
printf '%s' "$REGISTRY_PAT" | \
|
||||||
docker login git.bergerhouse.net \
|
docker login git.bergerhouse.net \
|
||||||
--username luckberg \
|
--username luckberg \
|
||||||
--password-stdin
|
--password-stdin
|
||||||
|
|||||||
Reference in New Issue
Block a user