From 9b56475656cdfd4d579c7ce18b24b26a6da29b79 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Sat, 26 Sep 2026 16:29:23 -0400 Subject: [PATCH] ci: print this repo's OIDC claim format --- .github/workflows/oidc-claims.yaml | 31 ++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) create mode 100644 .github/workflows/oidc-claims.yaml diff --git a/.github/workflows/oidc-claims.yaml b/.github/workflows/oidc-claims.yaml new file mode 100644 index 0000000..aaaa1e6 --- /dev/null +++ b/.github/workflows/oidc-claims.yaml @@ -0,0 +1,31 @@ +name: oidc-claims + +on: + pull_request: + branches: [main] + +permissions: + contents: read + id-token: write + +jobs: + claims: + runs-on: ubuntu-latest + steps: + - name: Print selected OIDC claims + run: | + set -euo pipefail + RESP="$(curl -fsS -H "Authorization: bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}" \ + "${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=sts.amazonaws.com")" + TOKEN="$(printf '%s' "${RESP}" | jq -r .value)" + echo "::add-mask::${TOKEN}" + PAYLOAD="$(printf '%s' "${TOKEN}" | cut -d. -f2)" + unset TOKEN RESP + python3 -c ' + import base64, json, sys + raw = sys.argv[1] + raw += "=" * (-len(raw) % 4) + data = json.loads(base64.urlsafe_b64decode(raw)) + keep = ["sub", "job_workflow_ref", "workflow_ref", "repository", "repository_id", "repository_owner_id"] + print(json.dumps({k: data.get(k) for k in keep}, indent=2)) + ' "${PAYLOAD}"