ci: print this repo's OIDC claim format

This commit is contained in:
Adam Moussa 2026-09-26 16:29:23 -04:00
parent f0a200f6e9
commit 9b56475656
No known key found for this signature in database

31
.github/workflows/oidc-claims.yaml vendored Normal file
View file

@ -0,0 +1,31 @@
name: oidc-claims
on:
pull_request:
branches: [main]
permissions:
contents: read
id-token: write
jobs:
claims:
runs-on: ubuntu-latest
steps:
- name: Print selected OIDC claims
run: |
set -euo pipefail
RESP="$(curl -fsS -H "Authorization: bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}" \
"${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=sts.amazonaws.com")"
TOKEN="$(printf '%s' "${RESP}" | jq -r .value)"
echo "::add-mask::${TOKEN}"
PAYLOAD="$(printf '%s' "${TOKEN}" | cut -d. -f2)"
unset TOKEN RESP
python3 -c '
import base64, json, sys
raw = sys.argv[1]
raw += "=" * (-len(raw) % 4)
data = json.loads(base64.urlsafe_b64decode(raw))
keep = ["sub", "job_workflow_ref", "workflow_ref", "repository", "repository_id", "repository_owner_id"]
print(json.dumps({k: data.get(k) for k in keep}, indent=2))
' "${PAYLOAD}"