fix(codex): 改由 job 層 env 從 secrets 注入 CODEX_OAUTH
CI / Release Tag Version (pull_request) Successful in 4s
CI / Codex (pull_request) Successful in 21s

composite action 內無法解析 secrets context(Gitea 與 GitHub 皆然,
vars 可、secrets 不可),導致 OAUTH 為空。改由呼叫端 workflow 在 job 層
以 env: CODEX_OAUTH: ${{ secrets.CODEX_OAUTH }} 注入,action 從繼承的
環境變數讀取並加空值把關;secret 仍源自 secrets、不經 inputs 傳遞。
This commit is contained in:
Jeffery
2026-06-29 13:35:42 +08:00
parent d05610d4e5
commit 08890b5b9d
2 changed files with 8 additions and 3 deletions
+2
View File
@@ -23,6 +23,8 @@ jobs:
name: Codex name: Codex
runs-on: ubuntu runs-on: ubuntu
needs: release-tag-version needs: release-tag-version
env:
CODEX_OAUTH: ${{ secrets.CODEX_OAUTH }}
steps: steps:
- name: 測試工具 - name: 測試工具
id: codex id: codex
+6 -3
View File
@@ -14,14 +14,17 @@ runs:
using: 'composite' using: 'composite'
steps: steps:
- name: 安裝工具 - name: 安裝工具
env:
OAUTH: ${{ secrets.CODEX_OAUTH }}
run: | run: |
if [ -z "$CODEX_OAUTH" ]; then
echo 'CODEX_OAUTH environment variable is required (set it from secrets.CODEX_OAUTH in the caller workflow).' >&2
exit 1
fi
npm install -g @openai/codex npm install -g @openai/codex
oauth_file="$HOME/.codex/auth.json" oauth_file="$HOME/.codex/auth.json"
install -d -m 700 "$(dirname "$oauth_file")" install -d -m 700 "$(dirname "$oauth_file")"
printf '%s' "$OAUTH" | base64 -d > "$oauth_file" printf '%s' "$CODEX_OAUTH" | base64 -d > "$oauth_file"
chmod 600 "$oauth_file" chmod 600 "$oauth_file"
shell: bash shell: bash
- name: 執行工具 - name: 執行工具