mirror of
https://github.com/docker/login-action.git
synced 2026-10-09 00:56:21 +02:00
chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
This commit is contained in:
2 files changed
+3
-3
No files matched your search
+1
-1
@@ -220,7 +220,7 @@ More info: ${l.url}`);let f=l.range&&l.range.length>0?l.range[0]?.start.line:voi
|
||||
`);let{connect:u,buffered:d}=await l;if(e.emit("proxyConnect",u),this.emit("proxyConnect",u,e),e.emit("proxy",{proxy:this.proxy.href,socket:s}),u.statusCode===200)return e.once("socket",iGe),r.secureEndpoint?(_f("Upgrading socket connection to TLS"),Dx.connect({...tK(yM(r),"host","path","port"),socket:s})):s;if(u.statusCode===407&&this.onProxyAuth){_f("Got 407 response, invoking onProxyAuth callback"),s.destroy();let m=u.headers["proxy-authenticate"]||"",f=Array.isArray(m)?m[0].split(/\s/)[0]:m.split(/\s/)[0],A=await this.onProxyAuth({response:u,scheme:f});return this._connectWithAuth(e,r,A.headers)}s.destroy();let p=new ll.Socket({writable:!1});return p.readable=!0,e.once("socket",m=>{_f("Replaying proxy buffer for failed request"),(0,aGe.default)(m.listenerCount("data")>0),m.push(d),m.push(null)}),p}async _connectWithAuth(e,r,n){let{proxy:s}=this,o;s.protocol==="https:"?o=Dx.connect(yM(this.connectOpts)):o=ll.connect(this.connectOpts);let a=typeof this.proxyHeaders=="function"?this.proxyHeaders():{...this.proxyHeaders},c=ll.isIPv6(r.host)?`[${r.host}]`:r.host,l=`CONNECT ${c}:${r.port} HTTP/1.1\r
|
||||
`;if(s.username||s.password){let p=`${decodeURIComponent(s.username)}:${decodeURIComponent(s.password)}`;a["Proxy-Authorization"]=`Basic ${Buffer.from(p).toString("base64")}`}Object.assign(a,n),a.Host=`${c}:${r.port}`,a["Proxy-Connection"]||(a["Proxy-Connection"]=this.keepAlive?"Keep-Alive":"close");for(let p of Object.keys(a))l+=`${p}: ${a[p]}\r
|
||||
`;let u=eK(o);o.write(`${l}\r
|
||||
`);let{connect:d}=await u;if(e.emit("proxyConnect",d),this.emit("proxyConnect",d,e),d.statusCode===200)return e.once("socket",iGe),r.secureEndpoint?(_f("Upgrading socket connection to TLS"),Dx.connect({...tK(yM(r),"host","path","port"),socket:o})):o;throw o.destroy(),new Error(`Proxy authentication failed with status ${d.statusCode} after retry`)}};kx.protocols=["http","https"];function iGe(t){setImmediate(()=>{t.resume()})}i(iGe,"resume");function tK(t,...e){let r={},n;for(n in t)e.includes(n)||(r[n]=t[n]);return r}i(tK,"omit");var nK=/^(([0-9]{12})\.(dkr\.ecr|dkr-ecr)\.(.+)\.(on\.aws|amazonaws\.(com(.cn)?|eu)))(\/([^:]+)(:.+)?)?$/,nHt=/public\.ecr\.aws|ecr-public\.aws\.com/,pGe=i(t=>nK.test(t)||EM(t),"isECR"),EM=i(t=>nHt.test(t),"isPubECR"),sHt=i(t=>{if(EM(t))return process.env.AWS_REGION||process.env.AWS_DEFAULT_REGION||"us-east-1";let e=t.match(nK);return e?e[4]:""},"getRegion"),oHt=i(t=>{if(EM(t))return[];let e=t.match(nK);if(!e)return[];let r=[e[2]];return process.env.AWS_ACCOUNT_IDS&&r.push(...process.env.AWS_ACCOUNT_IDS.split(",")),r.filter((n,s)=>r.indexOf(n)===s)},"getAccountIDs"),mGe=i(async(t,e,r)=>{let n=sHt(t),s=oHt(t),o={};s.length>0&&(v(`Requesting AWS ECR auth token for ${s.join(", ")}`),o.registryIds=s);let a,c=process.env.http_proxy||process.env.HTTP_PROXY||"";c&&(v(`Using http proxy ${c}`),a=new _x(c));let l,u=process.env.https_proxy||process.env.HTTPS_PROXY||"";u&&(v(`Using https proxy ${u}`),l=new kx(u));let d=e&&r?{accessKeyId:e,secretAccessKey:r}:void 0;if(EM(t)){Be(`AWS Public ECR detected with ${n} region`);let m=await new dGe.ECRPUBLIC({customUserAgent:"docker-login-action",credentials:d,region:n,requestHandler:new rK.NodeHttpHandler({httpAgent:a,httpsAgent:l})}).getAuthorizationToken(o);if(!m.authorizationData||!m.authorizationData.authorizationToken)throw new Error("Could not retrieve an authorization token from AWS Public ECR");let A=Buffer.from(m.authorizationData.authorizationToken,"base64").toString("utf-8").split(":",2);return Bn(A[0]),Bn(A[1]),[{registry:"public.ecr.aws",username:A[0],password:A[1]}]}else{Be(`AWS ECR detected with ${n} region`);let m=await new uGe.ECR({customUserAgent:"docker-login-action",credentials:d,region:n,requestHandler:new rK.NodeHttpHandler({httpAgent:a,httpsAgent:l})}).getAuthorizationToken(o);if(!Array.isArray(m.authorizationData)||!m.authorizationData.length)throw new Error("Could not retrieve an authorization token from AWS ECR");let f=[];for(let A of m.authorizationData){let E=Buffer.from(A.authorizationToken||"","base64").toString("utf-8").split(":",2);Bn(E[0]),Bn(E[1]),f.push({registry:A.proxyEndpoint||"",username:E[0],password:E[1]})}return f}},"getRegistriesData");var fGe=/^(?:[0-9a-f]{8}-[0-9a-f]{4}-[1-8][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$/i;function aHt(t){return typeof t=="string"&&fGe.test(t)}i(aHt,"validate");var sK=aHt;var cHt=new Set(["","docker.io","registry-1.docker.io","registry-1-stage.docker.io","dhi.io"]),lHt=300,AGe=300,hGe=3600,gGe=5,yGe=i((t,e)=>process.env.DOCKERHUB_OIDC_CONNECTIONID!==void 0&&!e&&cHt.has(t),"isDockerHubOIDC"),EGe=i(async(t,e)=>{let r=process.env.DOCKERHUB_OIDC_CONNECTIONID?.trim();if(!r)throw new Error("DOCKERHUB_OIDC_CONNECTIONID is required for Docker Hub OIDC login");if(!sK(r))throw new Error("Invalid DOCKERHUB_OIDC_CONNECTIONID. Must be a valid UUID.");let n=uHt(),s=t==="registry-1-stage.docker.io"?"identity-stage.docker.com":"identity.docker.com",o=`https://${s}`,a=await hoe(o),c=new so("github.com/docker/login-action",[],{headers:{"Content-Type":"application/x-www-form-urlencoded"}}),l=new URLSearchParams;l.set("grant_type","urn:ietf:params:oauth:grant-type:token-exchange"),l.set("subject_token_type","urn:ietf:params:oauth:token-type:id_token"),l.set("subject_token",a),l.set("connection_id",r),l.set("expires_in",n.toString());let u=await dHt(c,`https://${s}/oauth/token`,l.toString()),d=JSON.parse(await mHt(u));return Bn(d.access_token),{username:e,token:d.access_token}},"getOIDCToken"),uHt=i(()=>{let t=process.env.DOCKERHUB_OIDC_EXPIREIN?.trim()||lHt.toString(),e=Number(t);if(isNaN(e)||e<AGe||e>hGe)throw new Error(`Invalid DOCKERHUB_OIDC_EXPIREIN: ${t}. Must be between ${AGe} and ${hGe}`);return e},"getExpiresIn"),dHt=i(async(t,e,r)=>{let n=await t.post(e,r);for(let s=0;(n.message.statusCode||At.InternalServerError)===At.TooManyRequests&&s<gGe;s++){let o=pHt(n.message.headers["retry-after"]);if(o===null)break;await n.readBody(),Be(`Docker Hub OIDC token request rate limited, retrying in ${o}ms (attempt ${s+1}/${gGe})`),await new Promise(a=>setTimeout(a,o)),n=await t.post(e,r)}return n},"postWithRetry"),pHt=i(t=>{if(t===void 0)return null;Array.isArray(t)&&(t=t[0]);let e=Number(t);return isNaN(e)?null:Math.max(0,e*1e3)},"parseRetryAfter"),mHt=i(async t=>{let e=await t.readBody(),r=t.message.statusCode||At.InternalServerError;if(r<At.OK||r>=At.MultipleChoices)throw fHt(r,e);return e},"handleResponse"),fHt=i((t,e)=>{if
Line truncated
|
||||
`);let{connect:d}=await u;if(e.emit("proxyConnect",d),this.emit("proxyConnect",d,e),d.statusCode===200)return e.once("socket",iGe),r.secureEndpoint?(_f("Upgrading socket connection to TLS"),Dx.connect({...tK(yM(r),"host","path","port"),socket:o})):o;throw o.destroy(),new Error(`Proxy authentication failed with status ${d.statusCode} after retry`)}};kx.protocols=["http","https"];function iGe(t){setImmediate(()=>{t.resume()})}i(iGe,"resume");function tK(t,...e){let r={},n;for(n in t)e.includes(n)||(r[n]=t[n]);return r}i(tK,"omit");var nK=/^(([0-9]{12})\.(dkr\.ecr|dkr-ecr)\.(.+)\.(on\.aws|amazonaws\.(com(.cn)?|eu)))(\/([^:]+)(:.+)?)?$/,nHt=/public\.ecr\.aws|ecr-public\.aws\.com/,pGe=i(t=>nK.test(t)||EM(t),"isECR"),EM=i(t=>nHt.test(t),"isPubECR"),sHt=i(t=>{if(EM(t))return process.env.AWS_REGION||process.env.AWS_DEFAULT_REGION||"us-east-1";let e=t.match(nK);return e?e[4]:""},"getRegion"),oHt=i(t=>{if(EM(t))return[];let e=t.match(nK);if(!e)return[];let r=[e[2]];return process.env.AWS_ACCOUNT_IDS&&r.push(...process.env.AWS_ACCOUNT_IDS.split(",")),r.filter((n,s)=>r.indexOf(n)===s)},"getAccountIDs"),mGe=i(async(t,e,r)=>{let n=sHt(t),s=oHt(t),o={};s.length>0&&(v(`Requesting AWS ECR auth token for ${s.join(", ")}`),o.registryIds=s);let a,c=process.env.http_proxy||process.env.HTTP_PROXY||"";c&&(v(`Using http proxy ${c}`),a=new _x(c));let l,u=process.env.https_proxy||process.env.HTTPS_PROXY||"";u&&(v(`Using https proxy ${u}`),l=new kx(u));let d=e&&r?{accessKeyId:e,secretAccessKey:r}:void 0;if(EM(t)){Be(`AWS Public ECR detected with ${n} region`);let m=await new dGe.ECRPUBLIC({customUserAgent:"docker-login-action",credentials:d,region:n,requestHandler:new rK.NodeHttpHandler({httpAgent:a,httpsAgent:l})}).getAuthorizationToken(o);if(!m.authorizationData||!m.authorizationData.authorizationToken)throw new Error("Could not retrieve an authorization token from AWS Public ECR");let A=Buffer.from(m.authorizationData.authorizationToken,"base64").toString("utf-8").split(":",2);return Bn(A[0]),Bn(A[1]),[{registry:"public.ecr.aws",username:A[0],password:A[1]}]}else{Be(`AWS ECR detected with ${n} region`);let m=await new uGe.ECR({customUserAgent:"docker-login-action",credentials:d,region:n,requestHandler:new rK.NodeHttpHandler({httpAgent:a,httpsAgent:l})}).getAuthorizationToken(o);if(!Array.isArray(m.authorizationData)||!m.authorizationData.length)throw new Error("Could not retrieve an authorization token from AWS ECR");let f=[];for(let A of m.authorizationData){let E=Buffer.from(A.authorizationToken||"","base64").toString("utf-8").split(":",2);Bn(E[0]),Bn(E[1]),f.push({registry:A.proxyEndpoint||"",username:E[0],password:E[1]})}return f}},"getRegistriesData");var fGe=/^(?:[0-9a-f]{8}-[0-9a-f]{4}-[1-8][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$/i;function aHt(t){return typeof t=="string"&&fGe.test(t)}i(aHt,"validate");var sK=aHt;var cHt=new Set(["","docker.io","registry-1.docker.io","registry-1-stage.docker.io","dhi.io"]),lHt=300,AGe=300,hGe=21600,gGe=5,yGe=i((t,e)=>process.env.DOCKERHUB_OIDC_CONNECTIONID!==void 0&&!e&&cHt.has(t),"isDockerHubOIDC"),EGe=i(async(t,e)=>{let r=process.env.DOCKERHUB_OIDC_CONNECTIONID?.trim();if(!r)throw new Error("DOCKERHUB_OIDC_CONNECTIONID is required for Docker Hub OIDC login");if(!sK(r))throw new Error("Invalid DOCKERHUB_OIDC_CONNECTIONID. Must be a valid UUID.");let n=uHt(),s=t==="registry-1-stage.docker.io"?"identity-stage.docker.com":"identity.docker.com",o=`https://${s}`,a=await hoe(o),c=new so("github.com/docker/login-action",[],{headers:{"Content-Type":"application/x-www-form-urlencoded"}}),l=new URLSearchParams;l.set("grant_type","urn:ietf:params:oauth:grant-type:token-exchange"),l.set("subject_token_type","urn:ietf:params:oauth:token-type:id_token"),l.set("subject_token",a),l.set("connection_id",r),l.set("expires_in",n.toString());let u=await dHt(c,`https://${s}/oauth/token`,l.toString()),d=JSON.parse(await mHt(u));return Bn(d.access_token),{username:e,token:d.access_token}},"getOIDCToken"),uHt=i(()=>{let t=process.env.DOCKERHUB_OIDC_EXPIREIN?.trim()||lHt.toString(),e=Number(t);if(isNaN(e)||e<AGe||e>hGe)throw new Error(`Invalid DOCKERHUB_OIDC_EXPIREIN: ${t}. Must be between ${AGe} and ${hGe}`);return e},"getExpiresIn"),dHt=i(async(t,e,r)=>{let n=await t.post(e,r);for(let s=0;(n.message.statusCode||At.InternalServerError)===At.TooManyRequests&&s<gGe;s++){let o=pHt(n.message.headers["retry-after"]);if(o===null)break;await n.readBody(),Be(`Docker Hub OIDC token request rate limited, retrying in ${o}ms (attempt ${s+1}/${gGe})`),await new Promise(a=>setTimeout(a,o)),n=await t.post(e,r)}return n},"postWithRetry"),pHt=i(t=>{if(t===void 0)return null;Array.isArray(t)&&(t=t[0]);let e=Number(t);return isNaN(e)?null:Math.max(0,e*1e3)},"parseRetryAfter"),mHt=i(async t=>{let e=await t.readBody(),r=t.message.statusCode||At.InternalServerError;if(r<At.OK||r>=At.MultipleChoices)throw fHt(r,e);return e},"handleResponse"),fHt=i((t,e)=>{i
Line truncated
|
||||
/*! Bundled license information:
|
||||
|
||||
undici/lib/web/fetch/body.js:
|
||||
|
||||
Reference in new issue
Block a user