#!/usr/bin/env bash # Check out the product repositories at exact SHAs (spec §10). # # Repos under review are checked out at their PR head SHA. The companion repo of # a single-repo review is checked out at its default branch head for contract # context (spec §10.2) and recorded as such. # # Auth: the read-only App installation token is injected ONLY as a host-scoped # Basic http.extraHeader via GIT_CONFIG_* environment variables for the fetch # commands. It is never placed in a URL, never Bearer, and never written to # .git/config, so nothing credential-bearing persists after the run. # # Usage: checkout-repositories.sh # Reads: GH_TOKEN, REVIEW_TYPE, FRONTEND_REPO, BACKEND_REPO, # FRONTEND_SHA / BACKEND_SHA (empty when that side has no PR), # COMPANION_BRANCH (default: dev) SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" # shellcheck source=lib.sh source "$SCRIPT_DIR/lib.sh" require_env GH_TOKEN REVIEW_TYPE FRONTEND_REPO BACKEND_REPO COMPANION_BRANCH="${COMPANION_BRANCH:-dev}" # The Basic-auth header is a derived credential: GitHub masks the raw token it # minted, but not this transformation of it. Register the mask explicitly so an # accidental trace or debug flag cannot print a working credential to the log. AUTH_HEADER_B64="$(printf 'x-access-token:%s' "$GH_TOKEN" | base64 | tr -d '\n')" if [ -n "${GITHUB_ACTIONS:-}" ]; then echo "::add-mask::$AUTH_HEADER_B64" fi auth_git() { # git with the Basic auth header injected via env for this invocation only. GIT_CONFIG_COUNT=1 \ GIT_CONFIG_KEY_0="http.https://github.com/.extraHeader" \ GIT_CONFIG_VALUE_0="Authorization: Basic $AUTH_HEADER_B64" \ GIT_TERMINAL_PROMPT=0 \ git "$@" } # fetch_at