#!/usr/bin/env python3 #region FullFlow.GitBootstrap [C:4] [TYPE Module] [SEMANTICS gitea,fixture,publication,secrets] # @PURPOSE Create a real local Git publication repository and save its PAT in isolated credentials. # @PRE Gitea admin exists; the fixture env is mode 0600; localhost:18300 is the isolated Gitea. # @POST baseline-catalogs repository exists and deployment publication coordinates are saved. # @INVARIANT Credentials and tokens are never printed; existing credentials are reused unless rotation is explicit. import base64 import json import os import secrets from pathlib import Path import sys import urllib.error import urllib.request path = Path(sys.argv[1] if len(sys.argv) > 1 else '/tmp/ss-tools-full-flow.env') if path.stat().st_mode & 0o077: raise SystemExit('Fixture env must have mode 0600') values = dict(line.split('=', 1) for line in path.read_text().splitlines() if '=' in line) authorization = 'Basic ' + base64.b64encode(f'admin:{values["FIXTURE_PASSWORD"]}'.encode()).decode() # #region FullFlow.GitBootstrap.ApiRequest [C:2] [TYPE Function] # @BRIEF Call the isolated Gitea API with privately loaded fixture credentials. # @INVARIANT Credentials and response tokens are not printed. def call(route, payload=None): request = urllib.request.Request('http://127.0.0.1:18300/api/v1' + route, data=json.dumps(payload).encode() if payload is not None else None, headers={'Authorization':authorization,'Content-Type':'application/json'}) with urllib.request.urlopen(request, timeout=30) as response: return json.load(response) # #endregion FullFlow.GitBootstrap.ApiRequest try: call('/repos/admin/baseline-catalogs') except urllib.error.HTTPError as error: if error.code != 404: raise call('/user/repos', {'name':'baseline-catalogs','private':True,'auto_init':True,'default_branch':'main','description':'Isolated actual baseline publication evidence'}) if not values.get('PUBLISHED_CATALOG_GITEA_TOKEN') or '--rotate-token' in sys.argv[2:]: token = call('/users/admin/tokens', {'name':f'full-flow-publication-{secrets.token_hex(6)}','scopes':['write:repository','write:user']})['sha1'] values.update(PUBLISHED_CATALOG_GITEA_URL='http://gitea:3000', PUBLISHED_CATALOG_GITEA_TOKEN=token, PUBLISHED_CATALOG_REPO='admin/baseline-catalogs', PUBLISHED_CATALOG_REF='main') temporary = path.with_name(path.name + '.new') with os.fdopen(os.open(temporary, os.O_WRONLY | os.O_CREAT | os.O_EXCL, 0o600), 'w') as file: file.write(''.join(f'{key}={value}\n' for key, value in values.items())) os.replace(temporary, path) print('Local Git publication repository ready; credentials saved privately. Recreate backend to apply publication coordinates.') #endregion FullFlow.GitBootstrap