Use write access for owner check (#537)

This commit is contained in:
Joakim Sørensen
2020-07-03 19:08:07 +02:00
committed by GitHub
parent ae2a34f44c
commit 9846535768
5 changed files with 56 additions and 44 deletions
+21 -25
View File
@@ -1,26 +1,22 @@
{
"image": "ludeeus/container:python-base",
"context": "..",
"runArgs": [
"-v",
"${env:HOME}${env:USERPROFILE}/.ssh:/tmp/.ssh"
],
"extensions": [
"ms-python.python",
"github.vscode-pull-request-github",
"tabnine.tabnine-vscode"
],
"settings": {
"files.eol": "\n",
"editor.tabSize": 4,
"terminal.integrated.shell.linux": "/bin/bash",
"python.pythonPath": "/usr/local/bin/python",
"python.linting.pylintEnabled": true,
"python.linting.enabled": true,
"python.formatting.provider": "black",
"editor.formatOnPaste": false,
"editor.formatOnSave": true,
"editor.formatOnType": true,
"files.trimTrailingWhitespace": true
}
}
"image": "ludeeus/container:python-base",
"context": "..",
"extensions": [
"ms-python.python",
"github.vscode-pull-request-github",
"tabnine.tabnine-vscode"
],
"settings": {
"files.eol": "\n",
"editor.tabSize": 4,
"terminal.integrated.shell.linux": "/bin/bash",
"python.pythonPath": "/usr/local/bin/python",
"python.linting.pylintEnabled": true,
"python.linting.enabled": true,
"python.formatting.provider": "black",
"editor.formatOnPaste": false,
"editor.formatOnSave": true,
"editor.formatOnType": true,
"files.trimTrailingWhitespace": true
}
}
+13 -15
View File
@@ -10,7 +10,7 @@ jobs:
name: Initialize
outputs:
repository: ${{ steps.repository.outputs.repository }}
category: ${{ steps.category.outputs.category }}
category: ${{ steps.category.outputs.category }}
steps:
- name: Check out repository
uses: actions/checkout@v2
@@ -56,16 +56,16 @@ jobs:
fail-fast: False
matrix:
checks:
- {check: "archived", name: "Check Archived", deps: True}
- {check: "brands", name: "Check Brands", deps: True}
- {check: "fork", name: "Check Fork", deps: True}
- {check: "hacs_manifest", name: "Check HACS Manifest"}
- {check: "images", name: "Check Images"}
- {check: "info", name: "Check Info"}
- {check: "manifest", name: "Check Manifest"}
- {check: "owner", name: "Check Owner", deps: True}
- {check: "repository", name: "Check Repository", deps: True}
- {check: "wheels", name: "Check Wheels", deps: True}
- { check: "archived", name: "Check Archived", deps: True }
- { check: "brands", name: "Check Brands", deps: True }
- { check: "fork", name: "Check Fork", deps: True }
- { check: "hacs_manifest", name: "Check HACS Manifest" }
- { check: "images", name: "Check Images" }
- { check: "info", name: "Check Info" }
- { check: "manifest", name: "Check Manifest" }
- { check: "owner", name: "Check Owner", deps: True }
- { check: "repository", name: "Check Repository", deps: True }
- { check: "wheels", name: "Check Wheels", deps: True }
steps:
- name: Check out repository
uses: actions/checkout@v2
@@ -78,9 +78,7 @@ jobs:
- name: Install dependencies if needed
if: matrix.checks.deps
run: |
python3 -m pip install setuptools wheel
python3 -m pip install aiogithubapi
run: make init
- name: Run the check
run: python3 -m scripts.check.${{ matrix.checks.check }}
@@ -124,4 +122,4 @@ jobs:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
env:
REPOSITORY: ${{needs.preflight.outputs.repository}}
CATEGORY: ${{needs.preflight.outputs.category}}
CATEGORY: ${{needs.preflight.outputs.category}}
+4
View File
@@ -5,6 +5,10 @@ help: ## Shows help message.
@awk 'BEGIN {FS = ":.*##";} /^[a-zA-Z_-]+:.*?##/ { printf " \033[36m make %-15s\033[0m %s\n", $$1, $$2 } /^##@/ { printf "\n\033[1m%s\033[0m\n", substr($$0, 5) } ' $(MAKEFILE_LIST);
@echo
init:
python3 -m pip install setuptools wheel
python3 -m pip install -r requirements.txt
add: ## Add a new repository to the default HACS list
@echo script/add;
+1
View File
@@ -0,0 +1 @@
aiogithubapi==1.0.4
+17 -4
View File
@@ -3,6 +3,9 @@ import os
from scripts.changed.repo import get_repo
from scripts.helpers.event import get_event
from aiogithubapi import GitHub, AIOGitHubAPIException
TOKEN = os.getenv("GITHUB_TOKEN")
async def check():
@@ -11,11 +14,21 @@ async def check():
event = get_event()
actor = event["pull_request"]["user"]["login"]
if repo.split("/")[0] == event["pull_request"]["user"]["login"]:
print(f"{actor} is the owner of the repository")
return
try:
async with GitHub(TOKEN) as github:
request = await github.client.get(
endpoint=f"/repos/{repo}/collaborators/{actor}/permission", headers={},
)
exit(f"::warning::{actor} is not the owner of the repository")
permission = request.get("permission", "read")
if permission in ["admin", "write"]:
print(f"{actor} is the owner of the repository")
return
except AIOGitHubAPIException as e:
exit(f"::error::{e}")
exit(f"::error::{actor} does not have write access to the repository")
if __name__ == "__main__":