Keep the stored GitHub token when setup runs again
The secret store outlives the sandbox, so recreating one to change its image or add a profile does not lose the token. Prompting for a replacement anyway made --replace impractical and trained the habit of minting tokens that are never revoked. Only a token scoped to this sandbox counts. A global one would authenticate the agent too, but reaching every repository it can reach is what this task exists to prevent. The token command still always prompts; it is the way to replace an expired or revoked token.
This commit is contained in:
@@ -0,0 +1,90 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
TASK="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/tasks/ai/sbx"
|
||||
|
||||
# shellcheck source-path=SCRIPTDIR
|
||||
# shellcheck source=tasks/ai/sbx
|
||||
source "$TASK"
|
||||
|
||||
failures=0
|
||||
|
||||
fail() {
|
||||
printf 'FAIL: %s\n' "$1" >&2
|
||||
failures=$((failures + 1))
|
||||
}
|
||||
|
||||
SANDBOX_NAME=ai-repo-abc123
|
||||
|
||||
listing=""
|
||||
sbx() {
|
||||
printf '%s\n' "$listing"
|
||||
}
|
||||
|
||||
with_listing() {
|
||||
listing="$1"
|
||||
sandbox_has_github_token
|
||||
}
|
||||
|
||||
full_listing() {
|
||||
cat <<'EOF'
|
||||
SCOPE TYPE NAME SECRET
|
||||
ai-repo-abc123 service github (stored)
|
||||
(global) service anthropic (oauth configured)
|
||||
|
||||
CUSTOM SECRETS
|
||||
SCOPE TARGETS ENV PLACEHOLDER SECRET
|
||||
ai-repo-abc123 localstack.cloud LOCALSTACK_AUTH_TOKEN sbx-cs-0c2f39c1 ls-vOL***
|
||||
EOF
|
||||
}
|
||||
|
||||
with_listing "$(full_listing)" ||
|
||||
fail "a sandbox-scoped github token was not detected"
|
||||
|
||||
with_listing "$(
|
||||
cat <<'EOF'
|
||||
SCOPE TYPE NAME SECRET
|
||||
(global) service anthropic (oauth configured)
|
||||
EOF
|
||||
)" && fail "no github token stored, yet setup would have been skipped"
|
||||
|
||||
with_listing "$(
|
||||
cat <<'EOF'
|
||||
SCOPE TYPE NAME SECRET
|
||||
(global) service github (stored)
|
||||
EOF
|
||||
)" && fail "a global github token must not satisfy a per-repository sandbox"
|
||||
|
||||
with_listing "$(
|
||||
cat <<'EOF'
|
||||
SCOPE TYPE NAME SECRET
|
||||
ai-other-sandbox service github (stored)
|
||||
EOF
|
||||
)" && fail "another sandbox's github token must not count as this one's"
|
||||
|
||||
with_listing "$(
|
||||
cat <<'EOF'
|
||||
CUSTOM SECRETS
|
||||
SCOPE TARGETS ENV PLACEHOLDER SECRET
|
||||
ai-repo-abc123 github.com github sbx-cs-abc gh***
|
||||
EOF
|
||||
)" && fail "a custom secret must not be mistaken for the stored service token"
|
||||
|
||||
with_listing "" &&
|
||||
fail "empty output should mean no token, not a stored one"
|
||||
|
||||
grep -q 'if sandbox_has_github_token; then' "$TASK" ||
|
||||
fail "setup no longer guards install_github_token"
|
||||
|
||||
awk '/^token_command\(\)/, /^}/' "$TASK" | grep -q 'install_github_token' ||
|
||||
fail "the token command must always prompt; it is the way to replace one"
|
||||
|
||||
awk '/^token_command\(\)/, /^}/' "$TASK" | grep -q 'sandbox_has_github_token' &&
|
||||
fail "the token command must not skip when a token exists"
|
||||
|
||||
if ((failures)); then
|
||||
printf '%d assertion(s) failed\n' "$failures" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
printf 'All GitHub token assertions passed.\n'
|
||||
Reference in New Issue
Block a user