diff --git a/.github/workflows/pr-preview.yaml b/.github/workflows/pr-preview.yaml new file mode 100644 index 0000000..2ad2648 --- /dev/null +++ b/.github/workflows/pr-preview.yaml @@ -0,0 +1,63 @@ +name: Publish Extension Preview + +on: + workflow_run: + workflows: + - Build Extension Preview + types: + - completed + +permissions: + actions: read + contents: read + +concurrency: + group: publish-extension-preview-${{ github.event.workflow_run.head_repository.full_name }}-${{ github.event.workflow_run.head_branch }} + cancel-in-progress: true + +jobs: + publish: + if: >- + github.event.workflow_run.conclusion == 'success' && + github.event.workflow_run.event == 'pull_request' && + github.event.workflow_run.head_repository.full_name == github.repository + runs-on: ubuntu-latest + env: + BRANCH: ${{ github.event.workflow_run.head_branch }} + PREVIEW_BUCKET: samepage.network + REPOSITORY: ${{ github.repository }} + steps: + - name: download preview artifact + uses: actions/download-artifact@v6 + with: + github-token: ${{ secrets.GITHUB_TOKEN }} + name: extension-preview + path: preview + run-id: ${{ github.event.workflow_run.id }} + - name: validate preview artifact + shell: bash + run: | + test -f preview/extension.js + if find preview -type l -print -quit | grep -q .; then + echo "Preview artifacts must not contain symbolic links." + exit 1 + fi + - name: configure AWS credentials + uses: aws-actions/configure-aws-credentials@v4 + with: + aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} + aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} + aws-region: ${{ vars.AWS_REGION }} + - name: publish preview + shell: bash + run: | + prefix="releases/${REPOSITORY}/${BRANCH}/" + aws s3 cp preview "s3://${PREVIEW_BUCKET}/${prefix}" --recursive --no-follow-symlinks + + while IFS= read -r -d '' file; do + key="${prefix}${file#preview/}" + lowercase_key="$(printf '%s' "$key" | LC_ALL=C tr '[:upper:]' '[:lower:]')" + if [ "$key" != "$lowercase_key" ]; then + aws s3 cp "$file" "s3://${PREVIEW_BUCKET}/${lowercase_key}" --no-follow-symlinks + fi + done < <(find preview -type f -print0) diff --git a/.github/workflows/pr.yaml b/.github/workflows/pr.yaml index 927cd4c..0328177 100644 --- a/.github/workflows/pr.yaml +++ b/.github/workflows/pr.yaml @@ -1,17 +1,29 @@ -name: Publish Extension -on: pull_request +name: Build Extension Preview -env: - AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }} - AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }} - AWS_REGION: ${{ vars.AWS_REGION }} +on: + pull_request: + branches: + - main + +permissions: + contents: read + +concurrency: + group: build-extension-preview-${{ github.event.pull_request.number }} + cancel-in-progress: true jobs: - deploy: + build: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v6 - name: install run: npm install - name: build - run: npx samepage build + run: npx samepage build --dry + - name: upload preview artifact + uses: actions/upload-artifact@v6 + with: + name: extension-preview + path: dist/* + if-no-files-found: error