From 2c1588db566be8fc210e318d671ec81764044b9f Mon Sep 17 00:00:00 2001 From: Jens Tirsvad Nielsen Date: Sat, 3 Oct 2026 13:10:46 +0800 Subject: [PATCH] Improve GitHub credentials validation logic Add robust JSON parsing and type checking for GITHUB_CREDENTIALS environment variable, including handling missing, empty, or malformed input before attempting to extract token and user fields. --- .gitea/workflows/sync-github-metadata.yml | 31 ++++++++++++++++------- 1 file changed, 22 insertions(+), 9 deletions(-) diff --git a/.gitea/workflows/sync-github-metadata.yml b/.gitea/workflows/sync-github-metadata.yml index a5daba4..7651664 100644 --- a/.gitea/workflows/sync-github-metadata.yml +++ b/.gitea/workflows/sync-github-metadata.yml @@ -40,15 +40,28 @@ jobs: f"API request failed with HTTP {error.code} ({error.reason})" ) from None - credentials = json.loads(os.environ["GITHUB_CREDENTIALS"]) - github_token = credentials.get("GITHUB_PAT") - github_user = credentials.get("GITHUB_USER") - - if not github_token or not github_user: - raise RuntimeError( - "CREDENTIALS_FOR_GITHUB must contain GITHUB_PAT and GITHUB_USER." - ) - + raw_credentials = os.environ.get("GITHUB_CREDENTIALS", "").strip() + if not raw_credentials: + raise RuntimeError("CREDENTIALS_FOR_GITHUB is missing or empty.") + + try: + credentials = json.loads(raw_credentials) + except json.JSONDecodeError: + raise RuntimeError( + "CREDENTIALS_FOR_GITHUB must contain valid JSON." + ) from None + + if not isinstance(credentials, dict): + raise RuntimeError( + "CREDENTIALS_FOR_GITHUB must be a JSON object." + ) + + github_token = credentials.get("GITHUB_PAT") + github_user = credentials.get("GITHUB_USER") + if not github_token or not github_user: + raise RuntimeError( + "CREDENTIALS_FOR_GITHUB must contain GITHUB_PAT and GITHUB_USER." + ) source_owner, separator, source_repo = os.environ[ "SOURCE_REPOSITORY" ].partition("/")