mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-10-06 11:11:56 +00:00
ci: print this repo's OIDC claim format
This commit is contained in:
parent
f0a200f6e9
commit
9b56475656
1 changed files with 31 additions and 0 deletions
31
.github/workflows/oidc-claims.yaml
vendored
Normal file
31
.github/workflows/oidc-claims.yaml
vendored
Normal file
|
|
@ -0,0 +1,31 @@
|
||||||
|
name: oidc-claims
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
branches: [main]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
id-token: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
claims:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Print selected OIDC claims
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
RESP="$(curl -fsS -H "Authorization: bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}" \
|
||||||
|
"${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=sts.amazonaws.com")"
|
||||||
|
TOKEN="$(printf '%s' "${RESP}" | jq -r .value)"
|
||||||
|
echo "::add-mask::${TOKEN}"
|
||||||
|
PAYLOAD="$(printf '%s' "${TOKEN}" | cut -d. -f2)"
|
||||||
|
unset TOKEN RESP
|
||||||
|
python3 -c '
|
||||||
|
import base64, json, sys
|
||||||
|
raw = sys.argv[1]
|
||||||
|
raw += "=" * (-len(raw) % 4)
|
||||||
|
data = json.loads(base64.urlsafe_b64decode(raw))
|
||||||
|
keep = ["sub", "job_workflow_ref", "workflow_ref", "repository", "repository_id", "repository_owner_id"]
|
||||||
|
print(json.dumps({k: data.get(k) for k in keep}, indent=2))
|
||||||
|
' "${PAYLOAD}"
|
||||||
Loading…
Add table
Reference in a new issue