@samitouri / QOS-React-2 / commits / ba5dc6ccde

Add authorization header to artifacts request (#24106)

* Add authorization header to artifacts request CircleCI's artifacts API was updated; it now errors unless you're logged in. This affects any of our workflows that download build artifacts. To fix, I added an authorization header to the request. * Update sizbot to pull artifacts from public mirror We can't use the normal download-build script in sizebot because it depends on the CircleCI artifacts API, which was recently changed to require authorization. And we can't pass an authorization token without possibly leaking it to the public, since we run sizebot on PRs from external contributors. As a temporary workaround, this job will pull the artifacts from a public mirror that I set up. But we should find some other solution so we don't have to maintain the mirror.

Andrew Clark committed Mar 15, 2022 at 23:10 UTC ba5dc6ccde775e742643ac7da16ff5d4b29cc09c
2 files changed +19 -14
.circleci/config.yml
+10 -13
@@ -127,22 +127,19 @@ jobs:
127 environment: *environment
128 steps:
129 - checkout
130 - - run: yarn workspaces info | head -n -1 > workspace_info.txt
131 - - *restore_node_modules
130 - run:
131 name: Download artifacts for base revision
132 + # TODO: We can't use the normal download-build script here because it
133 + # depends on the CircleCI artifacts API, which was recently changed to
134 + # require authorization. And we can't pass an authorization token
135 + # without possibly leaking it to the public, since we run sizebot on
136 + # PRs from external contributors. As a temporary workaround, this job
137 + # will pull the artifacts from a public mirror that I set up. But we
138 + # should find some other solution so we don't have to maintain
139 + # the mirror.
140 command: |
135 - git fetch origin main
136 - cd ./scripts/release && yarn && cd ../../
137 - scripts/release/download-experimental-build.js --commit=$(git merge-base HEAD origin/main)
138 - mv ./build ./base-build
139 - - run:
140 - # TODO: The `download-experimental-build` script copies the npm
141 - # packages into the `node_modules` directory. This is a historical
142 - # quirk of how the release script works. Let's pretend they
143 - # don't exist.
144 - name: Delete extraneous files
145 - command: rm -rf ./base-build/node_modules
141 + curl -L --retry 60 --retry-delay 10 --retry-max-time 600 https://react-builds.vercel.app/api/commits/$(git merge-base HEAD origin/main)/artifacts/build.tgz | tar -xz
142 + mv ./build ./base-build
143
144 - persist_to_workspace:
145 root: .
scripts/release/shared-commands/download-build-artifacts.js
+9 -1
@@ -9,6 +9,14 @@ const {getArtifactsList, logPromise} = require('../utils');
9 const theme = require('../theme');
10
11 const run = async ({build, cwd, releaseChannel}) => {
12 + const CIRCLE_TOKEN = process.env.CIRCLE_CI_API_TOKEN;
13 + if (!CIRCLE_TOKEN) {
14 + console.error(
15 + theme.error('Missing required environment variable: CIRCLE_CI_API_TOKEN')
16 + );
17 + process.exit(1);
18 + }
19 +
20 const artifacts = await getArtifactsList(build);
21 const buildArtifacts = artifacts.find(entry =>
22 entry.path.endsWith('build.tgz')
@@ -24,7 +32,7 @@ const run = async ({build, cwd, releaseChannel}) => {
32 // Download and extract artifact
33 await exec(`rm -rf ./build`, {cwd});
34 await exec(
27 - `curl -L $(fwdproxy-config curl) ${buildArtifacts.url} | tar -xvz`,
35 + `curl -L $(fwdproxy-config curl) ${buildArtifacts.url} -H "Circle-Token: ${CIRCLE_TOKEN}" | tar -xvz`,
36 {
37 cwd,
38 }