mirror of
https://github.com/Z3Prover/z3
synced 2026-07-22 15:05:51 +00:00
Allow OTP input for WebAssembly npm publish workflow (#10156)
The `WebAssembly Publish` Actions job failed at `npm publish` with
`EOTP` because the workflow had no path to supply npm one-time passwords
for OTP-protected accounts. This change adds secure OTP input wiring for
manual publish runs while preserving the existing token-based flow.
- **Workflow dispatch input**
- Added optional `workflow_dispatch` input `npm_otp` in
`.github/workflows/wasm-release.yml`.
- **Secure OTP handling**
- Added a dedicated masking step so provided OTP values are redacted in
logs.
- Routed OTP to npm via `NPM_CONFIG_OTP` in the publish step
environment.
- **Publish step behavior**
- Kept publish command as `npm publish`; npm now consumes OTP
automatically when provided through env.
```yaml
on:
workflow_dispatch:
inputs:
npm_otp:
description: "One-time password for npm publish (optional)"
required: false
type: string
# ...
- name: Mask npm OTP
if: ${{ github.event.inputs.npm_otp != '' }}
run: echo "::add-mask::${{ github.event.inputs.npm_otp }}"
- name: Publish
run: npm publish
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
NPM_CONFIG_OTP: ${{ github.event.inputs.npm_otp }}
```
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
This commit is contained in:
parent
0d7376c733
commit
5a03a73685
1 changed files with 10 additions and 0 deletions
10
.github/workflows/wasm-release.yml
vendored
10
.github/workflows/wasm-release.yml
vendored
|
|
@ -2,6 +2,11 @@ name: WebAssembly Publish
|
|||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
npm_otp:
|
||||
description: "One-time password for npm publish (optional)"
|
||||
required: false
|
||||
type: string
|
||||
release:
|
||||
types: [published]
|
||||
|
||||
|
|
@ -61,7 +66,12 @@ jobs:
|
|||
- name: Test
|
||||
run: npm test
|
||||
|
||||
- name: Mask npm OTP
|
||||
if: ${{ github.event.inputs.npm_otp != '' }}
|
||||
run: echo "::add-mask::${{ github.event.inputs.npm_otp }}"
|
||||
|
||||
- name: Publish
|
||||
run: npm publish
|
||||
env:
|
||||
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
||||
NPM_CONFIG_OTP: ${{ github.event.inputs.npm_otp }}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue