mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-09-30 08:03:20 +00:00
31 lines
991 B
YAML
31 lines
991 B
YAML
name: oidc-claims
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
|
|
permissions:
|
|
contents: read
|
|
id-token: write
|
|
|
|
jobs:
|
|
claims:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Print selected OIDC claims
|
|
run: |
|
|
set -euo pipefail
|
|
RESP="$(curl -fsS -H "Authorization: bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}" \
|
|
"${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=sts.amazonaws.com")"
|
|
TOKEN="$(printf '%s' "${RESP}" | jq -r .value)"
|
|
echo "::add-mask::${TOKEN}"
|
|
PAYLOAD="$(printf '%s' "${TOKEN}" | cut -d. -f2)"
|
|
unset TOKEN RESP
|
|
python3 -c '
|
|
import base64, json, sys
|
|
raw = sys.argv[1]
|
|
raw += "=" * (-len(raw) % 4)
|
|
data = json.loads(base64.urlsafe_b64decode(raw))
|
|
keep = ["sub", "job_workflow_ref", "workflow_ref", "repository", "repository_id", "repository_owner_id"]
|
|
print(json.dumps({k: data.get(k) for k in keep}, indent=2))
|
|
' "${PAYLOAD}"
|