Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 30 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -120,8 +120,38 @@ platform).
- `publish` (optional, default `false`): Trigger the profile's publish flow.
- `appPath` (required when `upload` is `true`): Path to the application file. For
iOS use a `.ipa` file; for Android use a `.apk` or `.aab` file.
- `subOrganizationName` (optional): sub-organization to target with a root
organization token, see below.
- `authEndpoint` / `apiEndpoint` (optional): self-hosted endpoints, see below.

### Sub-Organizations

If your Personal API Token belongs to the root organization but the target
publish profile lives in a sub-organization, set the optional
`subOrganizationName` input. The action re-authenticates the same token against
that sub-organization and runs every subsequent call there, so the profile is
resolved in the sub-organization instead of the root organization.

```yml
- name: Upload and Publish to Appcircle
uses: appcircleio/appcircle-publish-githubaction
with:
personalAPIToken: ${{ secrets.AC_PERSONAL_API_TOKEN }}
subOrganizationName: YOUR_SUB_ORGANIZATION_NAME
platform: android
publishProfile: PUBLISH_PROFILE_NAME
upload: 'true'
publish: 'true'
appPath: ./app.aab
```

- `subOrganizationName`: Name of the sub-organization to target. Optional;
defaults to the root organization. The name must match exactly and the token
must have access to that sub-organization, otherwise the action fails instead
of falling back to the root organization.
It works the same way against a self-hosted installation; combine it with the
`authEndpoint` and `apiEndpoint` inputs described below.

### Self-Hosted Appcircle

If you run a self-hosted Appcircle installation, point the action to your own
Expand Down
7 changes: 7 additions & 0 deletions action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,13 @@ inputs:
Defaults to the Appcircle cloud.'
required: false
default: 'https://api.appcircle.io'
subOrganizationName:
description:
'Optional: Sub-organization name to target. Leave empty to use the root
organization. Use this when your Personal API Token belongs to the root
organization but the target publish profile lives in a sub-organization.'
required: false
default: ''
platform:
description: "Target platform of the publish profile: 'ios' or 'android'."
required: true
Expand Down
39 changes: 37 additions & 2 deletions dist/index.js

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion dist/index.js.map

Large diffs are not rendered by default.

10 changes: 8 additions & 2 deletions src/api/authApi.ts
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,20 @@ import axios from 'axios'

export async function getToken(
pat: string,
authEndpoint = 'https://auth.appcircle.io'
authEndpoint = 'https://auth.appcircle.io',
subOrganizationId?: string
): Promise<any> {
const params = new URLSearchParams()
params.append('pat', pat)

const tokenPath = subOrganizationId ? '/auth/v2/token' : '/auth/v1/token'
if (subOrganizationId) {
params.append('subOrganizationId', subOrganizationId)
}

const authHostname = authEndpoint.replace(/\/+$/, '')
const response = await axios.post(
`${authHostname}/auth/v1/token`,
`${authHostname}${tokenPath}`,
params.toString(),
{
headers: {
Expand Down
16 changes: 16 additions & 0 deletions src/api/publishApi.ts
Original file line number Diff line number Diff line change
Expand Up @@ -105,6 +105,22 @@ export class UploadServiceHeaders {
}
}

export async function getOrganizationId(name: string): Promise<string> {
const response = await appcircleApi.get('identity/v1/organizations', {
params: { page: 1, perPage: 1000 },
headers: UploadServiceHeaders.getHeaders()
})
const organizations: { id: string; name: string }[] =
response.data?.data ?? []
const organization = organizations.find(org => org.name === name)
if (!organization?.id) {
throw new Error(
`Sub-organization '${name}' could not be found or is not accessible with this token.`
)
}
return organization.id
}

export async function getPublishProfiles(platform: string) {
const response = await appcircleApi.get(`publish/v2/profiles/${platform}`, {
headers: UploadServiceHeaders.getHeaders()
Expand Down
27 changes: 27 additions & 0 deletions src/main.ts
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ import {
checkTaskStatus,
getActivePublishCountForProfile,
getLatestAppVersionId,
getOrganizationId,
getPublishId,
getPublishProfileId,
getReleaseCandidateVersionId,
Expand Down Expand Up @@ -36,6 +37,7 @@ export async function run(): Promise<void> {
const appPath = core.getInput('appPath')
const upload = asBool(core.getInput('upload'))
const publish = asBool(core.getInput('publish'))
const subOrganizationName = core.getInput('subOrganizationName')

setApiEndpoint(apiEndpoint)

Expand Down Expand Up @@ -75,6 +77,31 @@ export async function run(): Promise<void> {
UploadServiceHeaders.token = loginResponse.access_token
console.log('Logged in to Appcircle successfully')

if (subOrganizationName) {
const subOrganizationId = await getOrganizationId(subOrganizationName)
let subLoginResponse
try {
subLoginResponse = await getToken(
personalAPIToken,
authEndpoint,
subOrganizationId
)
} catch (error: any) {
const status = error?.response?.status
throw new Error(
`Could not authenticate against sub-organization '${subOrganizationName}'` +
`${status ? ` (HTTP ${status})` : ''}: ${error?.message}`
)
}
if (!subLoginResponse?.access_token) {
throw new Error(
`Could not obtain an access token for sub-organization '${subOrganizationName}'.`
)
}
UploadServiceHeaders.token = subLoginResponse.access_token
console.log(`Switched to sub-organization: ${subOrganizationName}`)
}

const publishProfileId = await getPublishProfileId({
platform,
publishProfileName: publishProfile
Expand Down
Loading