#!/usr/bin/env bash
# Check out the product repositories at exact SHAs (spec §10).
#
# Repos under review are checked out at their PR head SHA. The companion repo of
# a single-repo review is checked out at its default branch head for contract
# context (spec §10.2) and recorded as such.
#
# Auth: the read-only App installation token is injected ONLY as a host-scoped
# Basic http.extraHeader via GIT_CONFIG_* environment variables for the fetch
# commands. It is never placed in a URL, never Bearer, and never written to
# .git/config, so nothing credential-bearing persists after the run.
#
# Usage: checkout-repositories.sh
# Reads: GH_TOKEN, REVIEW_TYPE, FRONTEND_REPO, BACKEND_REPO,
# FRONTEND_SHA / BACKEND_SHA (empty when that side has no PR),
# COMPANION_BRANCH (default: dev)
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
# shellcheck source=lib.sh
source "$SCRIPT_DIR/lib.sh"
require_env GH_TOKEN REVIEW_TYPE FRONTEND_REPO BACKEND_REPO
COMPANION_BRANCH="${COMPANION_BRANCH:-dev}"
# The Basic-auth header is a derived credential: GitHub masks the raw token it
# minted, but not this transformation of it. Register the mask explicitly so an
# accidental trace or debug flag cannot print a working credential to the log.
AUTH_HEADER_B64="$(printf 'x-access-token:%s' "$GH_TOKEN" | base64 | tr -d '\n')"
if [ -n "${GITHUB_ACTIONS:-}" ]; then
echo "::add-mask::$AUTH_HEADER_B64"
fi
auth_git() {
# git with the Basic auth header injected via env for this invocation only.
GIT_CONFIG_COUNT=1 \
GIT_CONFIG_KEY_0="http.https://github.com/.extraHeader" \
GIT_CONFIG_VALUE_0="Authorization: Basic $AUTH_HEADER_B64" \
GIT_TERMINAL_PROMPT=0 \
git "$@"
}
# fetch_at