mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-09-30 08:03:20 +00:00
ci: print this repo's OIDC claim format
This commit is contained in:
parent
f0a200f6e9
commit
9b56475656
1 changed files with 31 additions and 0 deletions
31
.github/workflows/oidc-claims.yaml
vendored
Normal file
31
.github/workflows/oidc-claims.yaml
vendored
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
name: oidc-claims
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
|
||||
jobs:
|
||||
claims:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Print selected OIDC claims
|
||||
run: |
|
||||
set -euo pipefail
|
||||
RESP="$(curl -fsS -H "Authorization: bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}" \
|
||||
"${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=sts.amazonaws.com")"
|
||||
TOKEN="$(printf '%s' "${RESP}" | jq -r .value)"
|
||||
echo "::add-mask::${TOKEN}"
|
||||
PAYLOAD="$(printf '%s' "${TOKEN}" | cut -d. -f2)"
|
||||
unset TOKEN RESP
|
||||
python3 -c '
|
||||
import base64, json, sys
|
||||
raw = sys.argv[1]
|
||||
raw += "=" * (-len(raw) % 4)
|
||||
data = json.loads(base64.urlsafe_b64decode(raw))
|
||||
keep = ["sub", "job_workflow_ref", "workflow_ref", "repository", "repository_id", "repository_owner_id"]
|
||||
print(json.dumps({k: data.get(k) for k in keep}, indent=2))
|
||||
' "${PAYLOAD}"
|
||||
Loading…
Add table
Reference in a new issue