#!/bin/bash # ============================================================================= # officer-setup — the repository # ============================================================================= # # Definitions only. # # ── Cloned as the owner, never as root ── # # A repository cloned by root is one the owner cannot pull, cannot commit in, and # whose node_modules they cannot write. Every git operation here runs as the # account, from a directory that account can stat. [[ -n "${OFFICER_SETUP_REPO_LOADED:-}" ]] && return 0 OFFICER_SETUP_REPO_LOADED=1 OFFICER_REPO="${OFFICER_REPO:-ssh://git@gitea.officer.dev:2222/officerdev/platform.git}" platform_dir() { echo "${OFFICER_ROOT}/platform"; } repo_exists() { [[ -d "$(platform_dir)/.git" ]]; } repo_remote() { (cd "$(platform_dir)" 2>/dev/null && git remote get-url origin 2>/dev/null) || true; } repo_branch() { (cd "$(platform_dir)" 2>/dev/null && git branch --show-current 2>/dev/null) || true; } repo_is_dirty() { [[ -n "$(cd "$(platform_dir)" 2>/dev/null && git status --porcelain 2>/dev/null)" ]]; } # Split an ssh:// URL into host and port, for the reachability check below. repo_ssh_host() { sed -E 's|^ssh://[^@]*@([^:/]+).*|\1|' <<<"$1"; } repo_ssh_port() { sed -nE 's|^ssh://[^@]*@[^:]+:([0-9]+)/.*|\1|p' <<<"$1"; } # Can this account actually clone it? # # Checked before the clone rather than after, because an ssh URL with no usable # key does not fail cleanly — git either prompts for a password nobody is there # to type, or hangs on host-key verification. BatchMode turns both into an # immediate non-zero. # # Gitea answers a successful auth with a message and exit 1, so the test is # whether the SERVER recognised us, not the exit code. repo_ssh_ok() { local url="$1" host port out host="$(repo_ssh_host "$url")" port="$(repo_ssh_port "$url")" [[ -n "$host" ]] || return 1 out="$(as_owner "ssh -T -o BatchMode=yes -o StrictHostKeyChecking=accept-new -o ConnectTimeout=8 ${port:+-p $port} git@${host} 2>&1" || true)" grep -qiE "authenticated|successfully|welcome|does not provide shell access" <<<"$out" } # The https form of the same repository, for a machine with no key. repo_https_url() { sed -E 's|^ssh://[^@]*@([^:/]+)(:[0-9]+)?/|https://\1/|' <<<"$1" } clone_repo() { local url="$1" dest dest="$(platform_dir)" install -d -m 0755 -o "$USERNAME" -g "$(user_group)" "$OFFICER_ROOT" as_owner "git clone '${url}' '${dest}'" / } pull_repo() { as_owner "git -C '$(platform_dir)' pull --ff-only" /; }