abcxyz / abcxyz/github-token-minter

[minty action] String response from /token causes action to silently output an empty token

未关闭
#256 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
bug
主要语言
Go
星标
6
派生
2
PR 合并指标
30 天内没有已合并 PR

描述

### TL;DR

### Problem Description
When using `uses: abcxyz/github-token-minter/.github/actions/minty@main`, the step completes successfully (exit code 0), but:
1. The step output `${{ steps..outputs.token }}` is **empty / blank**.
2. The environment variable `MINTY_TOKEN` is **not set**.
3. The step logs a warning: `##[warning]Can't add secret mask for empty string in ##[add-mask] command.`
4. Downstream steps fail because no token was passed to them.

### Root Cause
In [`.github/actions/minty/main.js`](https://github.com/abcxyz/github-token-minter/blob/main/.github/actions/minty/main.js#L45-L63):

```javascript
const responseText = await response.text();

if (response.ok) {
try {
// expecting `{ "token": "TOKEN" }` format
const resp = JSON.parse(responseText);
core.setSecret(resp.token);
core.setOutput('token', resp.token);
core.saveState('MINTY_TOKEN', resp.token);
} catch (err) {
const token = responseText;
core.setSecret(token);
core.setOutput('token', token);
core.exportVariable('MINTY_TOKEN', token);
core.saveState('MINTY_TOKEN', token);
}
}
```

When `/token` returns a raw or JSON-quoted token string (e.g., `"ghs_1234567890abcdef"`):
1. `JSON.parse("\"ghs_1234567890abcdef\"")` succeeds without throwing, returning the primitive string `"ghs_1234567890abcdef"`.
2. `resp.token` evaluates to `undefined` because JavaScript strings do not have a `.token` property.
3. `core.setOutput('token', undefined)` silently sets the output to an empty string.
4. Because `JSON.parse` did not throw an error, the `catch` block (intended for raw strings) is never executed.

### Proposed Solution
Check if `resp` is an object with a `.token` property or a string before setting the output:

```javascript
let token = responseText;
try {
const resp = JSON.parse(responseText);
if (resp && typeof resp === 'object' && resp.token) {
token = resp.token;
} else if (typeof resp === 'string') {
token = resp;
}
} catch {
// Response was not JSON, use responseText as raw token string
}

core.setSecret(token);
core.setOutput('token', token);
core.exportVariable('MINTY_TOKEN', token);
core.saveState('MINTY_TOKEN', token);
```

### Expected behavior

_No response_

### Observed behavior

_No response_

### Environment Details

```markdown
internal instance.
```

### Additional information

_No response_

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。