Skip to content

Commit b064737

Browse files
committed
Generalize pygit2 remote callback handling
Signed-off-by: Tobias Wolf <wolf@b1-systems.de> On-behalf-of: SAP <tobias.wolf@sap.com>
1 parent e1109bb commit b064737

4 files changed

Lines changed: 85 additions & 81 deletions

File tree

‎src/gardenlinux/git/__init__.py‎

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,6 @@
44
Git module
55
"""
66

7-
from .credentials import Credentials
87
from .repository import Repository
98

10-
__all__ = ["Credentials", "Repository"]
9+
__all__ = ["Repository"]

‎src/gardenlinux/git/credentials.py‎

Lines changed: 0 additions & 74 deletions
This file was deleted.
Lines changed: 76 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,76 @@
1+
# -*- coding: utf-8 -*-
2+
3+
"""
4+
Git credentials provider
5+
"""
6+
7+
from typing import Any, Optional
8+
9+
from pygit2 import KeypairFromAgent, UserPass
10+
from pygit2 import RemoteCallbacks as _RemoteCallbacks
11+
from pygit2.enums import CredentialType
12+
13+
14+
class RemoteCallbacks(_RemoteCallbacks): # type: ignore[misc]
15+
"""
16+
pygit2.org: Base class for pygit2 remote callbacks.
17+
18+
:author: Garden Linux Maintainers
19+
:copyright: Copyright 2024 SAP SE
20+
:package: gardenlinux
21+
:subpackage: git
22+
:since: 1.0.0
23+
:license: https://www.apache.org/licenses/LICENSE-2.0
24+
Apache License, Version 2.0
25+
"""
26+
27+
def __init__(
28+
self,
29+
*args: Any,
30+
username: Optional[str] = None,
31+
password: Optional[str] = None,
32+
**kwargs: Any,
33+
):
34+
"""
35+
Constructor __init__(RemoteCallbacks)
36+
37+
:param token: GitHub/Git access token for HTTPS authentication.
38+
Falls back to the GITHUB_TOKEN environment variable if not provided.
39+
40+
:since: 1.0.0
41+
"""
42+
43+
self._username = ""
44+
self._password = ""
45+
46+
if username and password:
47+
self._username = username
48+
self._password = password
49+
50+
def credentials(
51+
self,
52+
url: str,
53+
username_from_url: Optional[str],
54+
allowed_types: CredentialType,
55+
) -> Optional[UserPass | KeypairFromAgent]:
56+
"""
57+
pygit2.org: Credentials callback. If the remote server requires
58+
authentication, this function will be called and its return value
59+
used for authentication.
60+
61+
:param url: The URL being accessed (after any insteadOf rewrites)
62+
:param username_from_url: Username extracted from the URL, if any
63+
:param allowed_types: Bitmask of credential types the server accepts
64+
65+
:return: A pygit2 credential object
66+
:since: 1.0.0
67+
"""
68+
69+
if allowed_types & CredentialType.USERPASS_PLAINTEXT:
70+
if self._password:
71+
return UserPass(self._username, self._password)
72+
73+
if allowed_types & CredentialType.SSH_KEY:
74+
return KeypairFromAgent(username_from_url or "git")
75+
76+
return _RemoteCallbacks.credentials(url, username_from_url, allowed_types)

‎src/gardenlinux/git/repository.py‎

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,17 @@
11
# -*- coding: utf-8 -*-
22

33
from logging import Logger
4-
from os import PathLike
4+
from os import environ, PathLike
55
from pathlib import Path
66
from typing import Any, List, Optional
77

8-
from pygit2 import Oid, RemoteCallbacks
8+
from pygit2 import Oid
99
from pygit2 import Repository as _Repository
1010
from pygit2 import init_repository
1111

1212
from ..constants import GL_REPOSITORY_URL
1313
from ..logger import LoggerSetup
14-
from .credentials import Credentials
14+
from .remote_callbacks import RemoteCallbacks
1515

1616

1717
class Repository(_Repository): # type: ignore[misc]
@@ -136,8 +136,11 @@ def checkout_repo(
136136
)
137137

138138
repo = init_repository(git_directory, origin_url=repo_url)
139-
callbacks = RemoteCallbacks(credentials=Credentials())
140-
repo.remotes["origin"].fetch(callbacks=callbacks)
139+
repo.remotes["origin"].fetch(
140+
callbacks=RemoteCallbacks(
141+
username=environ.get("GITHUB_TOKEN"), password="x-oauth-basic"
142+
)
143+
)
141144

142145
if commit is None:
143146
refish = f"origin/{branch}"

0 commit comments

Comments
 (0)