fix(ci): lib-forgejo TLS 校验默认开启,-k 改显式 opt-in(安全)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
wangjia
2026-07-05 23:55:56 +08:00
parent b8343a8788
commit ff8fc36726
+23 -3
View File
@@ -12,9 +12,29 @@
#
# No command substitution ($()) is used anywhere: HTTP status codes and JSON
# fields are written to temp files by curl/python3 and read back with `read`.
#
# TLS verification is ON by default. Opt-outs (env-driven, resolved once below
# into the FORGEJO_CURL_TLS array and spliced into every curl call):
# FORGEJO_CA_BUNDLE=<path> -> verify against this CA bundle (--cacert)
# FORGEJO_INSECURE=1 -> disable verification (-k), for self-signed
# internal CAs only; explicit opt-in required.
: "${FORGEJO_REPO:=wangjia/pangolin}"
FORGEJO_CURL_TLS=()
if [ -n "${FORGEJO_CA_BUNDLE:-}" ]; then
FORGEJO_CURL_TLS=(--cacert "$FORGEJO_CA_BUNDLE")
else
case "${FORGEJO_INSECURE:-}" in
1 | true | yes)
FORGEJO_CURL_TLS=(-k)
;;
*)
FORGEJO_CURL_TLS=()
;;
esac
fi
# forgejo_release_ensure <tag> <title>
forgejo_release_ensure() {
local tag="$1" title="$2"
@@ -23,7 +43,7 @@ forgejo_release_ensure() {
get_code_file="/tmp/forgejo_get_code.$$"
get_body_file="/tmp/forgejo_get_body.$$.json"
curl -k -s -o "$get_body_file" -w '%{http_code}' \
curl "${FORGEJO_CURL_TLS[@]}" -s -o "$get_body_file" -w '%{http_code}' \
-H "Authorization: token ${FORGEJO_TOKEN}" \
"${FORGEJO_URL}/api/v1/repos/${FORGEJO_REPO}/releases/tags/${tag}" \
> "$get_code_file"
@@ -43,7 +63,7 @@ forgejo_release_ensure() {
create_code_file="/tmp/forgejo_create_code.$$"
create_body_file="/tmp/forgejo_create_body.$$.json"
curl -k -s -o "$create_body_file" -w '%{http_code}' \
curl "${FORGEJO_CURL_TLS[@]}" -s -o "$create_body_file" -w '%{http_code}' \
-X POST "${FORGEJO_URL}/api/v1/repos/${FORGEJO_REPO}/releases" \
-H "Authorization: token ${FORGEJO_TOKEN}" \
-H "Content-Type: application/json" \
@@ -87,7 +107,7 @@ forgejo_upload_asset() {
code_file="/tmp/forgejo_upload_code.$$"
body_file="/tmp/forgejo_upload_body.$$.json"
curl -k -s -o "$body_file" -w '%{http_code}' \
curl "${FORGEJO_CURL_TLS[@]}" -s -o "$body_file" -w '%{http_code}' \
-X POST "${FORGEJO_URL}/api/v1/repos/${FORGEJO_REPO}/releases/${RELEASE_ID}/assets" \
-H "Authorization: token ${FORGEJO_TOKEN}" \
-F "attachment=@${file}" \