abcxyz / abcxyz/github-token-minter

[minty action] String response from /token causes action to silently output an empty token

Abierto
#256 0 comentarios 0 reacciones 0 asignados Ver en GitHub
bug
Lenguaje dominante
Go
Estrellas
6
Forks
2
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

### TL;DR

### Problem Description
When using `uses: abcxyz/github-token-minter/.github/actions/minty@main`, the step completes successfully (exit code 0), but:
1. The step output `${{ steps..outputs.token }}` is **empty / blank**.
2. The environment variable `MINTY_TOKEN` is **not set**.
3. The step logs a warning: `##[warning]Can't add secret mask for empty string in ##[add-mask] command.`
4. Downstream steps fail because no token was passed to them.

### Root Cause
In [`.github/actions/minty/main.js`](https://github.com/abcxyz/github-token-minter/blob/main/.github/actions/minty/main.js#L45-L63):

```javascript
const responseText = await response.text();

if (response.ok) {
try {
// expecting `{ "token": "TOKEN" }` format
const resp = JSON.parse(responseText);
core.setSecret(resp.token);
core.setOutput('token', resp.token);
core.saveState('MINTY_TOKEN', resp.token);
} catch (err) {
const token = responseText;
core.setSecret(token);
core.setOutput('token', token);
core.exportVariable('MINTY_TOKEN', token);
core.saveState('MINTY_TOKEN', token);
}
}
```

When `/token` returns a raw or JSON-quoted token string (e.g., `"ghs_1234567890abcdef"`):
1. `JSON.parse("\"ghs_1234567890abcdef\"")` succeeds without throwing, returning the primitive string `"ghs_1234567890abcdef"`.
2. `resp.token` evaluates to `undefined` because JavaScript strings do not have a `.token` property.
3. `core.setOutput('token', undefined)` silently sets the output to an empty string.
4. Because `JSON.parse` did not throw an error, the `catch` block (intended for raw strings) is never executed.

### Proposed Solution
Check if `resp` is an object with a `.token` property or a string before setting the output:

```javascript
let token = responseText;
try {
const resp = JSON.parse(responseText);
if (resp && typeof resp === 'object' && resp.token) {
token = resp.token;
} else if (typeof resp === 'string') {
token = resp;
}
} catch {
// Response was not JSON, use responseText as raw token string
}

core.setSecret(token);
core.setOutput('token', token);
core.exportVariable('MINTY_TOKEN', token);
core.saveState('MINTY_TOKEN', token);
```

### Expected behavior

_No response_

### Observed behavior

_No response_

### Environment Details

```markdown
internal instance.
```

### Additional information

_No response_

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.