From 5a03a73685f5d43727df2b25f417e2409b406764 Mon Sep 17 00:00:00 2001 From: Copilot <198982749+Copilot@users.noreply.github.com> Date: Fri, 17 Jul 2026 10:55:05 -0700 Subject: [PATCH] Allow OTP input for WebAssembly npm publish workflow (#10156) The `WebAssembly Publish` Actions job failed at `npm publish` with `EOTP` because the workflow had no path to supply npm one-time passwords for OTP-protected accounts. This change adds secure OTP input wiring for manual publish runs while preserving the existing token-based flow. - **Workflow dispatch input** - Added optional `workflow_dispatch` input `npm_otp` in `.github/workflows/wasm-release.yml`. - **Secure OTP handling** - Added a dedicated masking step so provided OTP values are redacted in logs. - Routed OTP to npm via `NPM_CONFIG_OTP` in the publish step environment. - **Publish step behavior** - Kept publish command as `npm publish`; npm now consumes OTP automatically when provided through env. ```yaml on: workflow_dispatch: inputs: npm_otp: description: "One-time password for npm publish (optional)" required: false type: string # ... - name: Mask npm OTP if: ${{ github.event.inputs.npm_otp != '' }} run: echo "::add-mask::${{ github.event.inputs.npm_otp }}" - name: Publish run: npm publish env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} NPM_CONFIG_OTP: ${{ github.event.inputs.npm_otp }} ``` --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> --- .github/workflows/wasm-release.yml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/.github/workflows/wasm-release.yml b/.github/workflows/wasm-release.yml index 9bed832a0..4ecba437e 100644 --- a/.github/workflows/wasm-release.yml +++ b/.github/workflows/wasm-release.yml @@ -2,6 +2,11 @@ name: WebAssembly Publish on: workflow_dispatch: + inputs: + npm_otp: + description: "One-time password for npm publish (optional)" + required: false + type: string release: types: [published] @@ -61,7 +66,12 @@ jobs: - name: Test run: npm test + - name: Mask npm OTP + if: ${{ github.event.inputs.npm_otp != '' }} + run: echo "::add-mask::${{ github.event.inputs.npm_otp }}" + - name: Publish run: npm publish env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} + NPM_CONFIG_OTP: ${{ github.event.inputs.npm_otp }}