Improve GitHub credentials validation logic
Sync GitHub mirror metadata / sync-metadata (push) Failing after 3s

Add robust JSON parsing and type checking for GITHUB_CREDENTIALS
environment variable, including handling missing, empty, or malformed
input before attempting to extract token and user fields.
This commit is contained in:
2026-10-03 13:10:46 +08:00
parent 1f01affc41
commit 2c1588db56
+22 -9
View File
@@ -40,15 +40,28 @@ jobs:
f"API request failed with HTTP {error.code} ({error.reason})"
) from None
credentials = json.loads(os.environ["GITHUB_CREDENTIALS"])
github_token = credentials.get("GITHUB_PAT")
github_user = credentials.get("GITHUB_USER")
if not github_token or not github_user:
raise RuntimeError(
"CREDENTIALS_FOR_GITHUB must contain GITHUB_PAT and GITHUB_USER."
)
raw_credentials = os.environ.get("GITHUB_CREDENTIALS", "").strip()
if not raw_credentials:
raise RuntimeError("CREDENTIALS_FOR_GITHUB is missing or empty.")
try:
credentials = json.loads(raw_credentials)
except json.JSONDecodeError:
raise RuntimeError(
"CREDENTIALS_FOR_GITHUB must contain valid JSON."
) from None
if not isinstance(credentials, dict):
raise RuntimeError(
"CREDENTIALS_FOR_GITHUB must be a JSON object."
)
github_token = credentials.get("GITHUB_PAT")
github_user = credentials.get("GITHUB_USER")
if not github_token or not github_user:
raise RuntimeError(
"CREDENTIALS_FOR_GITHUB must contain GITHUB_PAT and GITHUB_USER."
)
source_owner, separator, source_repo = os.environ[
"SOURCE_REPOSITORY"
].partition("/")