This repository was archived by the owner on Feb 18, 2024. It is now read-only.
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
91 changes: 48 additions & 43 deletions github.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,10 +33,11 @@ catch(e) {}
var execGit = require('./exec-git');

function createRemoteStrings(auth, hostname) {
var authString = auth ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
var authString = auth.username ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
hostname = hostname || 'github.com';

this.remoteString = 'https://' + authString + hostname + '/';
this.authSuffix = auth.token ? '?access_token=' + auth.token : '';

if (hostname == 'github.com')
this.apiRemoteString = 'https://' + authString + 'api.github.com/';
Expand All@@ -46,10 +47,6 @@ function createRemoteStrings(auth, hostname) {
this.apiRemoteString = 'https://' + authString + hostname + '/api/v3/';
}

// avoid storing passwords as plain text in config
function encodeCredentials(auth) {
return new Buffer(encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password)).toString('base64');
}
function decodeCredentials(str) {
var auth = new Buffer(str, 'base64').toString('ascii').split(':');

Expand DownExpand Up@@ -81,6 +78,10 @@ function readNetrc(hostname) {
}
}

function isGithubToken(token) {
return token.match(/[0-9a-f]{40}/);
}

var GithubLocation = function(options, ui) {

// ensure git is installed
Expand All@@ -98,19 +99,15 @@ var GithubLocation = function(options, ui) {
this.versionString = options.versionString + '.1';

// Give the environment precedence over options object
if(process.env.JSPM_GITHUB_AUTH_TOKEN) {
options.auth = process.env.JSPM_GITHUB_AUTH_TOKEN;
} else if (options.username && !options.auth) {
options.auth = encodeCredentials(options);
// NB deprecate old auth eventually
// delete options.username;
// delete options.password;
}
var auth = process.env.JSPM_GITHUB_AUTH_TOKEN || options.auth;

if (typeof options.auth == 'string') {
this.auth = decodeCredentials(options.auth);
}
else {
if (auth) {
if (isGithubToken(auth)) {
this.auth = { token: auth };
} else {
this.auth = decodeCredentials(auth);
}
} else {
this.auth = readNetrc(options.hostname);
}

Expand DownExpand Up@@ -148,7 +145,7 @@ var GithubLocation = function(options, ui) {

this.remote = options.remote;

createRemoteStrings.call(this, this.auth, options.hostname);
createRemoteStrings.call(this, this.auth || {}, options.hostname);
};

function clearDir(dir) {
Expand DownExpand Up@@ -199,20 +196,27 @@ function configureCredentials(config, ui) {

return Promise.resolve()
.then(function() {
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%. Ensure it has `public_repo` scope access.');
return ui.input('Enter your GitHub username');
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%.');
return ui.input('Enter your GitHub username or access token');
})
.then(function(username) {
auth.username = username;
if (auth.username)
return ui.input('Enter your GitHub password or access token', null, true);
.then(function(entered) {
if (!entered) {
return false;
} else if (isGithubToken(entered)) {
auth.token = entered;
} else {
auth.username = entered;
return ui.input('Enter your GitHub password', null, true);
}
})
.then(function(password) {
auth.password = password;
if (!auth.username)
return false;
if (password) {
auth.password = password;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again keep this code, with the prompt being Enter your GitHub username or access token as the first question, with the isGithubToken resulting in the new path (skipping password prompt), and otherwise the old path.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left this as-is (with the old code removed) since we don't need to allow this old stuff to go in.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Backwards compat should really mean the same prompts too I think.
On Sun, 12 Jun 2016 at 02:49, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Left this as-is (with the old code removed) since we don't need to allow
this old stuff to go in.


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714112,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiyrxzLDoQA_BvR-jvnJFmFE3VFUQcks5qK1eZgaJpZM4Izqxv
.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why? That means none of this can ever be deprecated or removed. We want to make sure people's existing configuration works, but why does that mean we need to support both forms forever?

That also creates a more confusing situation with the access tokens - if you use username/password you need to give public_repo, and otherwise you don't. Doesn't seem great

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Because the prompts form part of the public API.

If the PR was against the 0.17 branch for the jspm beta then we can
definitely consider doing that for 0.17. But on the 0.16 branch they should
remain as users expect now to be able to directly enter their github
username and password (which allows not having to go to the website to
create a token at all)
On Sun, 12 Jun 2016 at 02:54, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Why? That means none of this can ever be deprecated or removed. We want to
make sure people's existing configuration works, but why does that mean we
need to support both forms forever?

That also creates a more confusing situation with the access tokens - if
you use username/password you need to give public_repo, and otherwise you
don't. Doesn't seem great


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714150,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiykjKrj7oHuNSqxdXtl8EFq_VgRjXks5qK1izgaJpZM4Izqxv
.

@tamirdtamirdJun 12, 2016

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #91.


return ui.confirm('Would you like to test these credentials?', true);
if (auth.username || auth.token) {
return ui.confirm('Would you like to test these credentials?', true);
}
})
.then(function(test) {
if (!test)
Expand All@@ -224,7 +228,7 @@ function configureCredentials(config, ui) {
createRemoteStrings.call(remotes, auth, config.hostname);

return asp(request)({
uri: remotes.apiRemoteString + 'user',
uri: remotes.apiRemoteString + 'user' + remotes.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand DownExpand Up@@ -254,10 +258,10 @@ function configureCredentials(config, ui) {
.then(function(redo) {
if (redo)
return configureCredentials(config, ui);
return encodeCredentials(auth);
return auth.token;
});
else if (auth.username)
return encodeCredentials(auth);
else if (auth.token)
return auth.token;
else
return null;
});
Expand DownExpand Up@@ -328,14 +332,15 @@ GithubLocation.prototype = {
locate: function(repo) {
var self = this;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

if (repo.split('/').length !== 2)
throw "GitHub packages must be of the form `owner/repo`.";

// request the repo to check that it isn't a redirect
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo,
uri: remoteString + repo + authSuffix,
headers: {
'User-Agent': 'jspm'
},
Expand DownExpand Up@@ -433,7 +438,7 @@ GithubLocation.prototype = {
version = 'v' + version;

return asp(request)(extend({
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json',
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3.raw'
Expand DownExpand Up@@ -538,6 +543,7 @@ GithubLocation.prototype = {
var execOpt = this.execOpt;
var max_repo_size = this.max_repo_size;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

var self = this;

Expand DownExpand Up@@ -640,16 +646,12 @@ GithubLocation.prototype = {

// now that the inPipe is ready, do the request
request(extend({
uri: release.url,
uri: release.url + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
},
followRedirect: false,
auth: self.auth && {
user: self.auth.username,
pass: self.auth.password
}
}, self.defaultRequestOptions
)).on('response', function(archiveRes) {
var rateLimitResponse = checkRateLimit.call(this, archiveRes.headers);
Expand All@@ -660,7 +662,8 @@ GithubLocation.prototype = {
return reject('Bad response code ' + archiveRes.statusCode + '\n' + JSON.stringify(archiveRes.headers));

request(extend({
uri: archiveRes.headers.location, headers: {
uri: archiveRes.headers.location + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
}
Expand DownExpand Up@@ -692,8 +695,10 @@ GithubLocation.prototype = {
// Download from the git archive
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo + '/archive/' + version + '.tar.gz',
headers: { 'accept': 'application/octet-stream' }
uri: remoteString + repo + '/archive/' + version + '.tar.gz' + authSuffix,
headers: {
'accept': 'application/octet-stream'
},
}, self.defaultRequestOptions
))
.on('response', function(pkgRes) {
Expand DownExpand Up@@ -730,7 +735,7 @@ GithubLocation.prototype = {
checkReleases: function(repo, version) {
// NB cache this on disk with etags
var reqOptions = extend({
uri: this.apiRemoteString + 'repos/' + repo + '/releases',
uri: this.apiRemoteString + 'repos/' + repo + '/releases' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
91 changes: 48 additions & 43 deletions github.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,10 +33,11 @@ catch(e) {}
var execGit = require('./exec-git');

function createRemoteStrings(auth, hostname) {
var authString = auth ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
var authString = auth.username ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
hostname = hostname || 'github.com';

this.remoteString = 'https://' + authString + hostname + '/';
this.authSuffix = auth.token ? '?access_token=' + auth.token : '';

if (hostname == 'github.com')
this.apiRemoteString = 'https://' + authString + 'api.github.com/';
Expand All@@ -46,10 +47,6 @@ function createRemoteStrings(auth, hostname) {
this.apiRemoteString = 'https://' + authString + hostname + '/api/v3/';
}

// avoid storing passwords as plain text in config
function encodeCredentials(auth) {
return new Buffer(encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password)).toString('base64');
}
function decodeCredentials(str) {
var auth = new Buffer(str, 'base64').toString('ascii').split(':');

Expand DownExpand Up@@ -81,6 +78,10 @@ function readNetrc(hostname) {
}
}

function isGithubToken(token) {
return token.match(/[0-9a-f]{40}/);
}

var GithubLocation = function(options, ui) {

// ensure git is installed
Expand All@@ -98,19 +99,15 @@ var GithubLocation = function(options, ui) {
this.versionString = options.versionString + '.1';

// Give the environment precedence over options object
if(process.env.JSPM_GITHUB_AUTH_TOKEN) {
options.auth = process.env.JSPM_GITHUB_AUTH_TOKEN;
} else if (options.username && !options.auth) {
options.auth = encodeCredentials(options);
// NB deprecate old auth eventually
// delete options.username;
// delete options.password;
}
var auth = process.env.JSPM_GITHUB_AUTH_TOKEN || options.auth;

if (typeof options.auth == 'string') {
this.auth = decodeCredentials(options.auth);
}
else {
if (auth) {
if (isGithubToken(auth)) {
this.auth = { token: auth };
} else {
this.auth = decodeCredentials(auth);
}
} else {
this.auth = readNetrc(options.hostname);
}

Expand DownExpand Up@@ -148,7 +145,7 @@ var GithubLocation = function(options, ui) {

this.remote = options.remote;

createRemoteStrings.call(this, this.auth, options.hostname);
createRemoteStrings.call(this, this.auth || {}, options.hostname);
};

function clearDir(dir) {
Expand DownExpand Up@@ -199,20 +196,27 @@ function configureCredentials(config, ui) {

return Promise.resolve()
.then(function() {
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%. Ensure it has `public_repo` scope access.');
return ui.input('Enter your GitHub username');
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%.');
return ui.input('Enter your GitHub username or access token');
})
.then(function(username) {
auth.username = username;
if (auth.username)
return ui.input('Enter your GitHub password or access token', null, true);
.then(function(entered) {
if (!entered) {
return false;
} else if (isGithubToken(entered)) {
auth.token = entered;
} else {
auth.username = entered;
return ui.input('Enter your GitHub password', null, true);
}
})
.then(function(password) {
auth.password = password;
if (!auth.username)
return false;
if (password) {
auth.password = password;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again keep this code, with the prompt being Enter your GitHub username or access token as the first question, with the isGithubToken resulting in the new path (skipping password prompt), and otherwise the old path.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left this as-is (with the old code removed) since we don't need to allow this old stuff to go in.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Backwards compat should really mean the same prompts too I think.
On Sun, 12 Jun 2016 at 02:49, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Left this as-is (with the old code removed) since we don't need to allow
this old stuff to go in.


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714112,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiyrxzLDoQA_BvR-jvnJFmFE3VFUQcks5qK1eZgaJpZM4Izqxv
.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why? That means none of this can ever be deprecated or removed. We want to make sure people's existing configuration works, but why does that mean we need to support both forms forever?

That also creates a more confusing situation with the access tokens - if you use username/password you need to give public_repo, and otherwise you don't. Doesn't seem great

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Because the prompts form part of the public API.

If the PR was against the 0.17 branch for the jspm beta then we can
definitely consider doing that for 0.17. But on the 0.16 branch they should
remain as users expect now to be able to directly enter their github
username and password (which allows not having to go to the website to
create a token at all)
On Sun, 12 Jun 2016 at 02:54, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Why? That means none of this can ever be deprecated or removed. We want to
make sure people's existing configuration works, but why does that mean we
need to support both forms forever?

That also creates a more confusing situation with the access tokens - if
you use username/password you need to give public_repo, and otherwise you
don't. Doesn't seem great


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714150,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiykjKrj7oHuNSqxdXtl8EFq_VgRjXks5qK1izgaJpZM4Izqxv
.

@tamirdtamirdJun 12, 2016

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #91.


return ui.confirm('Would you like to test these credentials?', true);
if (auth.username || auth.token) {
return ui.confirm('Would you like to test these credentials?', true);
}
})
.then(function(test) {
if (!test)
Expand All@@ -224,7 +228,7 @@ function configureCredentials(config, ui) {
createRemoteStrings.call(remotes, auth, config.hostname);

return asp(request)({
uri: remotes.apiRemoteString + 'user',
uri: remotes.apiRemoteString + 'user' + remotes.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand DownExpand Up@@ -254,10 +258,10 @@ function configureCredentials(config, ui) {
.then(function(redo) {
if (redo)
return configureCredentials(config, ui);
return encodeCredentials(auth);
return auth.token;
});
else if (auth.username)
return encodeCredentials(auth);
else if (auth.token)
return auth.token;
else
return null;
});
Expand DownExpand Up@@ -328,14 +332,15 @@ GithubLocation.prototype = {
locate: function(repo) {
var self = this;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

if (repo.split('/').length !== 2)
throw "GitHub packages must be of the form `owner/repo`.";

// request the repo to check that it isn't a redirect
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo,
uri: remoteString + repo + authSuffix,
headers: {
'User-Agent': 'jspm'
},
Expand DownExpand Up@@ -433,7 +438,7 @@ GithubLocation.prototype = {
version = 'v' + version;

return asp(request)(extend({
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json',
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3.raw'
Expand DownExpand Up@@ -538,6 +543,7 @@ GithubLocation.prototype = {
var execOpt = this.execOpt;
var max_repo_size = this.max_repo_size;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

var self = this;

Expand DownExpand Up@@ -640,16 +646,12 @@ GithubLocation.prototype = {

// now that the inPipe is ready, do the request
request(extend({
uri: release.url,
uri: release.url + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
},
followRedirect: false,
auth: self.auth && {
user: self.auth.username,
pass: self.auth.password
}
}, self.defaultRequestOptions
)).on('response', function(archiveRes) {
var rateLimitResponse = checkRateLimit.call(this, archiveRes.headers);
Expand All@@ -660,7 +662,8 @@ GithubLocation.prototype = {
return reject('Bad response code ' + archiveRes.statusCode + '\n' + JSON.stringify(archiveRes.headers));

request(extend({
uri: archiveRes.headers.location, headers: {
uri: archiveRes.headers.location + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
}
Expand DownExpand Up@@ -692,8 +695,10 @@ GithubLocation.prototype = {
// Download from the git archive
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo + '/archive/' + version + '.tar.gz',
headers: { 'accept': 'application/octet-stream' }
uri: remoteString + repo + '/archive/' + version + '.tar.gz' + authSuffix,
headers: {
'accept': 'application/octet-stream'
},
}, self.defaultRequestOptions
))
.on('response', function(pkgRes) {
Expand DownExpand Up@@ -730,7 +735,7 @@ GithubLocation.prototype = {
checkReleases: function(repo, version) {
// NB cache this on disk with etags
var reqOptions = extend({
uri: this.apiRemoteString + 'repos/' + repo + '/releases',
uri: this.apiRemoteString + 'repos/' + repo + '/releases' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
91 changes: 48 additions & 43 deletions github.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,10 +33,11 @@ catch(e) {}
var execGit = require('./exec-git');

function createRemoteStrings(auth, hostname) {
var authString = auth ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
var authString = auth.username ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
hostname = hostname || 'github.com';

this.remoteString = 'https://' + authString + hostname + '/';
this.authSuffix = auth.token ? '?access_token=' + auth.token : '';

if (hostname == 'github.com')
this.apiRemoteString = 'https://' + authString + 'api.github.com/';
Expand All@@ -46,10 +47,6 @@ function createRemoteStrings(auth, hostname) {
this.apiRemoteString = 'https://' + authString + hostname + '/api/v3/';
}

// avoid storing passwords as plain text in config
function encodeCredentials(auth) {
return new Buffer(encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password)).toString('base64');
}
function decodeCredentials(str) {
var auth = new Buffer(str, 'base64').toString('ascii').split(':');

Expand DownExpand Up@@ -81,6 +78,10 @@ function readNetrc(hostname) {
}
}

function isGithubToken(token) {
return token.match(/[0-9a-f]{40}/);
}

var GithubLocation = function(options, ui) {

// ensure git is installed
Expand All@@ -98,19 +99,15 @@ var GithubLocation = function(options, ui) {
this.versionString = options.versionString + '.1';

// Give the environment precedence over options object
if(process.env.JSPM_GITHUB_AUTH_TOKEN) {
options.auth = process.env.JSPM_GITHUB_AUTH_TOKEN;
} else if (options.username && !options.auth) {
options.auth = encodeCredentials(options);
// NB deprecate old auth eventually
// delete options.username;
// delete options.password;
}
var auth = process.env.JSPM_GITHUB_AUTH_TOKEN || options.auth;

if (typeof options.auth == 'string') {
this.auth = decodeCredentials(options.auth);
}
else {
if (auth) {
if (isGithubToken(auth)) {
this.auth = { token: auth };
} else {
this.auth = decodeCredentials(auth);
}
} else {
this.auth = readNetrc(options.hostname);
}

Expand DownExpand Up@@ -148,7 +145,7 @@ var GithubLocation = function(options, ui) {

this.remote = options.remote;

createRemoteStrings.call(this, this.auth, options.hostname);
createRemoteStrings.call(this, this.auth || {}, options.hostname);
};

function clearDir(dir) {
Expand DownExpand Up@@ -199,20 +196,27 @@ function configureCredentials(config, ui) {

return Promise.resolve()
.then(function() {
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%. Ensure it has `public_repo` scope access.');
return ui.input('Enter your GitHub username');
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%.');
return ui.input('Enter your GitHub username or access token');
})
.then(function(username) {
auth.username = username;
if (auth.username)
return ui.input('Enter your GitHub password or access token', null, true);
.then(function(entered) {
if (!entered) {
return false;
} else if (isGithubToken(entered)) {
auth.token = entered;
} else {
auth.username = entered;
return ui.input('Enter your GitHub password', null, true);
}
})
.then(function(password) {
auth.password = password;
if (!auth.username)
return false;
if (password) {
auth.password = password;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again keep this code, with the prompt being Enter your GitHub username or access token as the first question, with the isGithubToken resulting in the new path (skipping password prompt), and otherwise the old path.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left this as-is (with the old code removed) since we don't need to allow this old stuff to go in.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Backwards compat should really mean the same prompts too I think.
On Sun, 12 Jun 2016 at 02:49, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Left this as-is (with the old code removed) since we don't need to allow
this old stuff to go in.


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714112,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiyrxzLDoQA_BvR-jvnJFmFE3VFUQcks5qK1eZgaJpZM4Izqxv
.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why? That means none of this can ever be deprecated or removed. We want to make sure people's existing configuration works, but why does that mean we need to support both forms forever?

That also creates a more confusing situation with the access tokens - if you use username/password you need to give public_repo, and otherwise you don't. Doesn't seem great

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Because the prompts form part of the public API.

If the PR was against the 0.17 branch for the jspm beta then we can
definitely consider doing that for 0.17. But on the 0.16 branch they should
remain as users expect now to be able to directly enter their github
username and password (which allows not having to go to the website to
create a token at all)
On Sun, 12 Jun 2016 at 02:54, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Why? That means none of this can ever be deprecated or removed. We want to
make sure people's existing configuration works, but why does that mean we
need to support both forms forever?

That also creates a more confusing situation with the access tokens - if
you use username/password you need to give public_repo, and otherwise you
don't. Doesn't seem great


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714150,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiykjKrj7oHuNSqxdXtl8EFq_VgRjXks5qK1izgaJpZM4Izqxv
.

@tamirdtamirdJun 12, 2016

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #91.


return ui.confirm('Would you like to test these credentials?', true);
if (auth.username || auth.token) {
return ui.confirm('Would you like to test these credentials?', true);
}
})
.then(function(test) {
if (!test)
Expand All@@ -224,7 +228,7 @@ function configureCredentials(config, ui) {
createRemoteStrings.call(remotes, auth, config.hostname);

return asp(request)({
uri: remotes.apiRemoteString + 'user',
uri: remotes.apiRemoteString + 'user' + remotes.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand DownExpand Up@@ -254,10 +258,10 @@ function configureCredentials(config, ui) {
.then(function(redo) {
if (redo)
return configureCredentials(config, ui);
return encodeCredentials(auth);
return auth.token;
});
else if (auth.username)
return encodeCredentials(auth);
else if (auth.token)
return auth.token;
else
return null;
});
Expand DownExpand Up@@ -328,14 +332,15 @@ GithubLocation.prototype = {
locate: function(repo) {
var self = this;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

if (repo.split('/').length !== 2)
throw "GitHub packages must be of the form `owner/repo`.";

// request the repo to check that it isn't a redirect
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo,
uri: remoteString + repo + authSuffix,
headers: {
'User-Agent': 'jspm'
},
Expand DownExpand Up@@ -433,7 +438,7 @@ GithubLocation.prototype = {
version = 'v' + version;

return asp(request)(extend({
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json',
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3.raw'
Expand DownExpand Up@@ -538,6 +543,7 @@ GithubLocation.prototype = {
var execOpt = this.execOpt;
var max_repo_size = this.max_repo_size;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

var self = this;

Expand DownExpand Up@@ -640,16 +646,12 @@ GithubLocation.prototype = {

// now that the inPipe is ready, do the request
request(extend({
uri: release.url,
uri: release.url + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
},
followRedirect: false,
auth: self.auth && {
user: self.auth.username,
pass: self.auth.password
}
}, self.defaultRequestOptions
)).on('response', function(archiveRes) {
var rateLimitResponse = checkRateLimit.call(this, archiveRes.headers);
Expand All@@ -660,7 +662,8 @@ GithubLocation.prototype = {
return reject('Bad response code ' + archiveRes.statusCode + '\n' + JSON.stringify(archiveRes.headers));

request(extend({
uri: archiveRes.headers.location, headers: {
uri: archiveRes.headers.location + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
}
Expand DownExpand Up@@ -692,8 +695,10 @@ GithubLocation.prototype = {
// Download from the git archive
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo + '/archive/' + version + '.tar.gz',
headers: { 'accept': 'application/octet-stream' }
uri: remoteString + repo + '/archive/' + version + '.tar.gz' + authSuffix,
headers: {
'accept': 'application/octet-stream'
},
}, self.defaultRequestOptions
))
.on('response', function(pkgRes) {
Expand DownExpand Up@@ -730,7 +735,7 @@ GithubLocation.prototype = {
checkReleases: function(repo, version) {
// NB cache this on disk with etags
var reqOptions = extend({
uri: this.apiRemoteString + 'repos/' + repo + '/releases',
uri: this.apiRemoteString + 'repos/' + repo + '/releases' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
91 changes: 48 additions & 43 deletions github.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,10 +33,11 @@ catch(e) {}
var execGit = require('./exec-git');

function createRemoteStrings(auth, hostname) {
var authString = auth ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
var authString = auth.username ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
hostname = hostname || 'github.com';

this.remoteString = 'https://' + authString + hostname + '/';
this.authSuffix = auth.token ? '?access_token=' + auth.token : '';

if (hostname == 'github.com')
this.apiRemoteString = 'https://' + authString + 'api.github.com/';
Expand All@@ -46,10 +47,6 @@ function createRemoteStrings(auth, hostname) {
this.apiRemoteString = 'https://' + authString + hostname + '/api/v3/';
}

// avoid storing passwords as plain text in config
function encodeCredentials(auth) {
return new Buffer(encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password)).toString('base64');
}
function decodeCredentials(str) {
var auth = new Buffer(str, 'base64').toString('ascii').split(':');

Expand DownExpand Up@@ -81,6 +78,10 @@ function readNetrc(hostname) {
}
}

function isGithubToken(token) {
return token.match(/[0-9a-f]{40}/);
}

var GithubLocation = function(options, ui) {

// ensure git is installed
Expand All@@ -98,19 +99,15 @@ var GithubLocation = function(options, ui) {
this.versionString = options.versionString + '.1';

// Give the environment precedence over options object
if(process.env.JSPM_GITHUB_AUTH_TOKEN) {
options.auth = process.env.JSPM_GITHUB_AUTH_TOKEN;
} else if (options.username && !options.auth) {
options.auth = encodeCredentials(options);
// NB deprecate old auth eventually
// delete options.username;
// delete options.password;
}
var auth = process.env.JSPM_GITHUB_AUTH_TOKEN || options.auth;

if (typeof options.auth == 'string') {
this.auth = decodeCredentials(options.auth);
}
else {
if (auth) {
if (isGithubToken(auth)) {
this.auth = { token: auth };
} else {
this.auth = decodeCredentials(auth);
}
} else {
this.auth = readNetrc(options.hostname);
}

Expand DownExpand Up@@ -148,7 +145,7 @@ var GithubLocation = function(options, ui) {

this.remote = options.remote;

createRemoteStrings.call(this, this.auth, options.hostname);
createRemoteStrings.call(this, this.auth || {}, options.hostname);
};

function clearDir(dir) {
Expand DownExpand Up@@ -199,20 +196,27 @@ function configureCredentials(config, ui) {

return Promise.resolve()
.then(function() {
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%. Ensure it has `public_repo` scope access.');
return ui.input('Enter your GitHub username');
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%.');
return ui.input('Enter your GitHub username or access token');
})
.then(function(username) {
auth.username = username;
if (auth.username)
return ui.input('Enter your GitHub password or access token', null, true);
.then(function(entered) {
if (!entered) {
return false;
} else if (isGithubToken(entered)) {
auth.token = entered;
} else {
auth.username = entered;
return ui.input('Enter your GitHub password', null, true);
}
})
.then(function(password) {
auth.password = password;
if (!auth.username)
return false;
if (password) {
auth.password = password;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again keep this code, with the prompt being Enter your GitHub username or access token as the first question, with the isGithubToken resulting in the new path (skipping password prompt), and otherwise the old path.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left this as-is (with the old code removed) since we don't need to allow this old stuff to go in.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Backwards compat should really mean the same prompts too I think.
On Sun, 12 Jun 2016 at 02:49, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Left this as-is (with the old code removed) since we don't need to allow
this old stuff to go in.


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714112,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiyrxzLDoQA_BvR-jvnJFmFE3VFUQcks5qK1eZgaJpZM4Izqxv
.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why? That means none of this can ever be deprecated or removed. We want to make sure people's existing configuration works, but why does that mean we need to support both forms forever?

That also creates a more confusing situation with the access tokens - if you use username/password you need to give public_repo, and otherwise you don't. Doesn't seem great

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Because the prompts form part of the public API.

If the PR was against the 0.17 branch for the jspm beta then we can
definitely consider doing that for 0.17. But on the 0.16 branch they should
remain as users expect now to be able to directly enter their github
username and password (which allows not having to go to the website to
create a token at all)
On Sun, 12 Jun 2016 at 02:54, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Why? That means none of this can ever be deprecated or removed. We want to
make sure people's existing configuration works, but why does that mean we
need to support both forms forever?

That also creates a more confusing situation with the access tokens - if
you use username/password you need to give public_repo, and otherwise you
don't. Doesn't seem great


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714150,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiykjKrj7oHuNSqxdXtl8EFq_VgRjXks5qK1izgaJpZM4Izqxv
.

@tamirdtamirdJun 12, 2016

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #91.


return ui.confirm('Would you like to test these credentials?', true);
if (auth.username || auth.token) {
return ui.confirm('Would you like to test these credentials?', true);
}
})
.then(function(test) {
if (!test)
Expand All@@ -224,7 +228,7 @@ function configureCredentials(config, ui) {
createRemoteStrings.call(remotes, auth, config.hostname);

return asp(request)({
uri: remotes.apiRemoteString + 'user',
uri: remotes.apiRemoteString + 'user' + remotes.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand DownExpand Up@@ -254,10 +258,10 @@ function configureCredentials(config, ui) {
.then(function(redo) {
if (redo)
return configureCredentials(config, ui);
return encodeCredentials(auth);
return auth.token;
});
else if (auth.username)
return encodeCredentials(auth);
else if (auth.token)
return auth.token;
else
return null;
});
Expand DownExpand Up@@ -328,14 +332,15 @@ GithubLocation.prototype = {
locate: function(repo) {
var self = this;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

if (repo.split('/').length !== 2)
throw "GitHub packages must be of the form `owner/repo`.";

// request the repo to check that it isn't a redirect
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo,
uri: remoteString + repo + authSuffix,
headers: {
'User-Agent': 'jspm'
},
Expand DownExpand Up@@ -433,7 +438,7 @@ GithubLocation.prototype = {
version = 'v' + version;

return asp(request)(extend({
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json',
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3.raw'
Expand DownExpand Up@@ -538,6 +543,7 @@ GithubLocation.prototype = {
var execOpt = this.execOpt;
var max_repo_size = this.max_repo_size;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

var self = this;

Expand DownExpand Up@@ -640,16 +646,12 @@ GithubLocation.prototype = {

// now that the inPipe is ready, do the request
request(extend({
uri: release.url,
uri: release.url + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
},
followRedirect: false,
auth: self.auth && {
user: self.auth.username,
pass: self.auth.password
}
}, self.defaultRequestOptions
)).on('response', function(archiveRes) {
var rateLimitResponse = checkRateLimit.call(this, archiveRes.headers);
Expand All@@ -660,7 +662,8 @@ GithubLocation.prototype = {
return reject('Bad response code ' + archiveRes.statusCode + '\n' + JSON.stringify(archiveRes.headers));

request(extend({
uri: archiveRes.headers.location, headers: {
uri: archiveRes.headers.location + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
}
Expand DownExpand Up@@ -692,8 +695,10 @@ GithubLocation.prototype = {
// Download from the git archive
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo + '/archive/' + version + '.tar.gz',
headers: { 'accept': 'application/octet-stream' }
uri: remoteString + repo + '/archive/' + version + '.tar.gz' + authSuffix,
headers: {
'accept': 'application/octet-stream'
},
}, self.defaultRequestOptions
))
.on('response', function(pkgRes) {
Expand DownExpand Up@@ -730,7 +735,7 @@ GithubLocation.prototype = {
checkReleases: function(repo, version) {
// NB cache this on disk with etags
var reqOptions = extend({
uri: this.apiRemoteString + 'repos/' + repo + '/releases',
uri: this.apiRemoteString + 'repos/' + repo + '/releases' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
91 changes: 48 additions & 43 deletions github.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,10 +33,11 @@ catch(e) {}
var execGit = require('./exec-git');

function createRemoteStrings(auth, hostname) {
var authString = auth ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
var authString = auth.username ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
hostname = hostname || 'github.com';

this.remoteString = 'https://' + authString + hostname + '/';
this.authSuffix = auth.token ? '?access_token=' + auth.token : '';

if (hostname == 'github.com')
this.apiRemoteString = 'https://' + authString + 'api.github.com/';
Expand All@@ -46,10 +47,6 @@ function createRemoteStrings(auth, hostname) {
this.apiRemoteString = 'https://' + authString + hostname + '/api/v3/';
}

// avoid storing passwords as plain text in config
function encodeCredentials(auth) {
return new Buffer(encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password)).toString('base64');
}
function decodeCredentials(str) {
var auth = new Buffer(str, 'base64').toString('ascii').split(':');

Expand DownExpand Up@@ -81,6 +78,10 @@ function readNetrc(hostname) {
}
}

function isGithubToken(token) {
return token.match(/[0-9a-f]{40}/);
}

var GithubLocation = function(options, ui) {

// ensure git is installed
Expand All@@ -98,19 +99,15 @@ var GithubLocation = function(options, ui) {
this.versionString = options.versionString + '.1';

// Give the environment precedence over options object
if(process.env.JSPM_GITHUB_AUTH_TOKEN) {
options.auth = process.env.JSPM_GITHUB_AUTH_TOKEN;
} else if (options.username && !options.auth) {
options.auth = encodeCredentials(options);
// NB deprecate old auth eventually
// delete options.username;
// delete options.password;
}
var auth = process.env.JSPM_GITHUB_AUTH_TOKEN || options.auth;

if (typeof options.auth == 'string') {
this.auth = decodeCredentials(options.auth);
}
else {
if (auth) {
if (isGithubToken(auth)) {
this.auth = { token: auth };
} else {
this.auth = decodeCredentials(auth);
}
} else {
this.auth = readNetrc(options.hostname);
}

Expand DownExpand Up@@ -148,7 +145,7 @@ var GithubLocation = function(options, ui) {

this.remote = options.remote;

createRemoteStrings.call(this, this.auth, options.hostname);
createRemoteStrings.call(this, this.auth || {}, options.hostname);
};

function clearDir(dir) {
Expand DownExpand Up@@ -199,20 +196,27 @@ function configureCredentials(config, ui) {

return Promise.resolve()
.then(function() {
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%. Ensure it has `public_repo` scope access.');
return ui.input('Enter your GitHub username');
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%.');
return ui.input('Enter your GitHub username or access token');
})
.then(function(username) {
auth.username = username;
if (auth.username)
return ui.input('Enter your GitHub password or access token', null, true);
.then(function(entered) {
if (!entered) {
return false;
} else if (isGithubToken(entered)) {
auth.token = entered;
} else {
auth.username = entered;
return ui.input('Enter your GitHub password', null, true);
}
})
.then(function(password) {
auth.password = password;
if (!auth.username)
return false;
if (password) {
auth.password = password;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again keep this code, with the prompt being Enter your GitHub username or access token as the first question, with the isGithubToken resulting in the new path (skipping password prompt), and otherwise the old path.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left this as-is (with the old code removed) since we don't need to allow this old stuff to go in.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Backwards compat should really mean the same prompts too I think.
On Sun, 12 Jun 2016 at 02:49, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Left this as-is (with the old code removed) since we don't need to allow
this old stuff to go in.


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714112,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiyrxzLDoQA_BvR-jvnJFmFE3VFUQcks5qK1eZgaJpZM4Izqxv
.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why? That means none of this can ever be deprecated or removed. We want to make sure people's existing configuration works, but why does that mean we need to support both forms forever?

That also creates a more confusing situation with the access tokens - if you use username/password you need to give public_repo, and otherwise you don't. Doesn't seem great

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Because the prompts form part of the public API.

If the PR was against the 0.17 branch for the jspm beta then we can
definitely consider doing that for 0.17. But on the 0.16 branch they should
remain as users expect now to be able to directly enter their github
username and password (which allows not having to go to the website to
create a token at all)
On Sun, 12 Jun 2016 at 02:54, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Why? That means none of this can ever be deprecated or removed. We want to
make sure people's existing configuration works, but why does that mean we
need to support both forms forever?

That also creates a more confusing situation with the access tokens - if
you use username/password you need to give public_repo, and otherwise you
don't. Doesn't seem great


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714150,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiykjKrj7oHuNSqxdXtl8EFq_VgRjXks5qK1izgaJpZM4Izqxv
.

@tamirdtamirdJun 12, 2016

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #91.


return ui.confirm('Would you like to test these credentials?', true);
if (auth.username || auth.token) {
return ui.confirm('Would you like to test these credentials?', true);
}
})
.then(function(test) {
if (!test)
Expand All@@ -224,7 +228,7 @@ function configureCredentials(config, ui) {
createRemoteStrings.call(remotes, auth, config.hostname);

return asp(request)({
uri: remotes.apiRemoteString + 'user',
uri: remotes.apiRemoteString + 'user' + remotes.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand DownExpand Up@@ -254,10 +258,10 @@ function configureCredentials(config, ui) {
.then(function(redo) {
if (redo)
return configureCredentials(config, ui);
return encodeCredentials(auth);
return auth.token;
});
else if (auth.username)
return encodeCredentials(auth);
else if (auth.token)
return auth.token;
else
return null;
});
Expand DownExpand Up@@ -328,14 +332,15 @@ GithubLocation.prototype = {
locate: function(repo) {
var self = this;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

if (repo.split('/').length !== 2)
throw "GitHub packages must be of the form `owner/repo`.";

// request the repo to check that it isn't a redirect
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo,
uri: remoteString + repo + authSuffix,
headers: {
'User-Agent': 'jspm'
},
Expand DownExpand Up@@ -433,7 +438,7 @@ GithubLocation.prototype = {
version = 'v' + version;

return asp(request)(extend({
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json',
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3.raw'
Expand DownExpand Up@@ -538,6 +543,7 @@ GithubLocation.prototype = {
var execOpt = this.execOpt;
var max_repo_size = this.max_repo_size;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

var self = this;

Expand DownExpand Up@@ -640,16 +646,12 @@ GithubLocation.prototype = {

// now that the inPipe is ready, do the request
request(extend({
uri: release.url,
uri: release.url + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
},
followRedirect: false,
auth: self.auth && {
user: self.auth.username,
pass: self.auth.password
}
}, self.defaultRequestOptions
)).on('response', function(archiveRes) {
var rateLimitResponse = checkRateLimit.call(this, archiveRes.headers);
Expand All@@ -660,7 +662,8 @@ GithubLocation.prototype = {
return reject('Bad response code ' + archiveRes.statusCode + '\n' + JSON.stringify(archiveRes.headers));

request(extend({
uri: archiveRes.headers.location, headers: {
uri: archiveRes.headers.location + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
}
Expand DownExpand Up@@ -692,8 +695,10 @@ GithubLocation.prototype = {
// Download from the git archive
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo + '/archive/' + version + '.tar.gz',
headers: { 'accept': 'application/octet-stream' }
uri: remoteString + repo + '/archive/' + version + '.tar.gz' + authSuffix,
headers: {
'accept': 'application/octet-stream'
},
}, self.defaultRequestOptions
))
.on('response', function(pkgRes) {
Expand DownExpand Up@@ -730,7 +735,7 @@ GithubLocation.prototype = {
checkReleases: function(repo, version) {
// NB cache this on disk with etags
var reqOptions = extend({
uri: this.apiRemoteString + 'repos/' + repo + '/releases',
uri: this.apiRemoteString + 'repos/' + repo + '/releases' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
91 changes: 48 additions & 43 deletions github.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,10 +33,11 @@ catch(e) {}
var execGit = require('./exec-git');

function createRemoteStrings(auth, hostname) {
var authString = auth ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
var authString = auth.username ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
hostname = hostname || 'github.com';

this.remoteString = 'https://' + authString + hostname + '/';
this.authSuffix = auth.token ? '?access_token=' + auth.token : '';

if (hostname == 'github.com')
this.apiRemoteString = 'https://' + authString + 'api.github.com/';
Expand All@@ -46,10 +47,6 @@ function createRemoteStrings(auth, hostname) {
this.apiRemoteString = 'https://' + authString + hostname + '/api/v3/';
}

// avoid storing passwords as plain text in config
function encodeCredentials(auth) {
return new Buffer(encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password)).toString('base64');
}
function decodeCredentials(str) {
var auth = new Buffer(str, 'base64').toString('ascii').split(':');

Expand DownExpand Up@@ -81,6 +78,10 @@ function readNetrc(hostname) {
}
}

function isGithubToken(token) {
return token.match(/[0-9a-f]{40}/);
}

var GithubLocation = function(options, ui) {

// ensure git is installed
Expand All@@ -98,19 +99,15 @@ var GithubLocation = function(options, ui) {
this.versionString = options.versionString + '.1';

// Give the environment precedence over options object
if(process.env.JSPM_GITHUB_AUTH_TOKEN) {
options.auth = process.env.JSPM_GITHUB_AUTH_TOKEN;
} else if (options.username && !options.auth) {
options.auth = encodeCredentials(options);
// NB deprecate old auth eventually
// delete options.username;
// delete options.password;
}
var auth = process.env.JSPM_GITHUB_AUTH_TOKEN || options.auth;

if (typeof options.auth == 'string') {
this.auth = decodeCredentials(options.auth);
}
else {
if (auth) {
if (isGithubToken(auth)) {
this.auth = { token: auth };
} else {
this.auth = decodeCredentials(auth);
}
} else {
this.auth = readNetrc(options.hostname);
}

Expand DownExpand Up@@ -148,7 +145,7 @@ var GithubLocation = function(options, ui) {

this.remote = options.remote;

createRemoteStrings.call(this, this.auth, options.hostname);
createRemoteStrings.call(this, this.auth || {}, options.hostname);
};

function clearDir(dir) {
Expand DownExpand Up@@ -199,20 +196,27 @@ function configureCredentials(config, ui) {

return Promise.resolve()
.then(function() {
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%. Ensure it has `public_repo` scope access.');
return ui.input('Enter your GitHub username');
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%.');
return ui.input('Enter your GitHub username or access token');
})
.then(function(username) {
auth.username = username;
if (auth.username)
return ui.input('Enter your GitHub password or access token', null, true);
.then(function(entered) {
if (!entered) {
return false;
} else if (isGithubToken(entered)) {
auth.token = entered;
} else {
auth.username = entered;
return ui.input('Enter your GitHub password', null, true);
}
})
.then(function(password) {
auth.password = password;
if (!auth.username)
return false;
if (password) {
auth.password = password;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again keep this code, with the prompt being Enter your GitHub username or access token as the first question, with the isGithubToken resulting in the new path (skipping password prompt), and otherwise the old path.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left this as-is (with the old code removed) since we don't need to allow this old stuff to go in.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Backwards compat should really mean the same prompts too I think.
On Sun, 12 Jun 2016 at 02:49, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Left this as-is (with the old code removed) since we don't need to allow
this old stuff to go in.


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714112,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiyrxzLDoQA_BvR-jvnJFmFE3VFUQcks5qK1eZgaJpZM4Izqxv
.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why? That means none of this can ever be deprecated or removed. We want to make sure people's existing configuration works, but why does that mean we need to support both forms forever?

That also creates a more confusing situation with the access tokens - if you use username/password you need to give public_repo, and otherwise you don't. Doesn't seem great

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Because the prompts form part of the public API.

If the PR was against the 0.17 branch for the jspm beta then we can
definitely consider doing that for 0.17. But on the 0.16 branch they should
remain as users expect now to be able to directly enter their github
username and password (which allows not having to go to the website to
create a token at all)
On Sun, 12 Jun 2016 at 02:54, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Why? That means none of this can ever be deprecated or removed. We want to
make sure people's existing configuration works, but why does that mean we
need to support both forms forever?

That also creates a more confusing situation with the access tokens - if
you use username/password you need to give public_repo, and otherwise you
don't. Doesn't seem great


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714150,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiykjKrj7oHuNSqxdXtl8EFq_VgRjXks5qK1izgaJpZM4Izqxv
.

@tamirdtamirdJun 12, 2016

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #91.


return ui.confirm('Would you like to test these credentials?', true);
if (auth.username || auth.token) {
return ui.confirm('Would you like to test these credentials?', true);
}
})
.then(function(test) {
if (!test)
Expand All@@ -224,7 +228,7 @@ function configureCredentials(config, ui) {
createRemoteStrings.call(remotes, auth, config.hostname);

return asp(request)({
uri: remotes.apiRemoteString + 'user',
uri: remotes.apiRemoteString + 'user' + remotes.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand DownExpand Up@@ -254,10 +258,10 @@ function configureCredentials(config, ui) {
.then(function(redo) {
if (redo)
return configureCredentials(config, ui);
return encodeCredentials(auth);
return auth.token;
});
else if (auth.username)
return encodeCredentials(auth);
else if (auth.token)
return auth.token;
else
return null;
});
Expand DownExpand Up@@ -328,14 +332,15 @@ GithubLocation.prototype = {
locate: function(repo) {
var self = this;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

if (repo.split('/').length !== 2)
throw "GitHub packages must be of the form `owner/repo`.";

// request the repo to check that it isn't a redirect
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo,
uri: remoteString + repo + authSuffix,
headers: {
'User-Agent': 'jspm'
},
Expand DownExpand Up@@ -433,7 +438,7 @@ GithubLocation.prototype = {
version = 'v' + version;

return asp(request)(extend({
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json',
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3.raw'
Expand DownExpand Up@@ -538,6 +543,7 @@ GithubLocation.prototype = {
var execOpt = this.execOpt;
var max_repo_size = this.max_repo_size;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

var self = this;

Expand DownExpand Up@@ -640,16 +646,12 @@ GithubLocation.prototype = {

// now that the inPipe is ready, do the request
request(extend({
uri: release.url,
uri: release.url + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
},
followRedirect: false,
auth: self.auth && {
user: self.auth.username,
pass: self.auth.password
}
}, self.defaultRequestOptions
)).on('response', function(archiveRes) {
var rateLimitResponse = checkRateLimit.call(this, archiveRes.headers);
Expand All@@ -660,7 +662,8 @@ GithubLocation.prototype = {
return reject('Bad response code ' + archiveRes.statusCode + '\n' + JSON.stringify(archiveRes.headers));

request(extend({
uri: archiveRes.headers.location, headers: {
uri: archiveRes.headers.location + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
}
Expand DownExpand Up@@ -692,8 +695,10 @@ GithubLocation.prototype = {
// Download from the git archive
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo + '/archive/' + version + '.tar.gz',
headers: { 'accept': 'application/octet-stream' }
uri: remoteString + repo + '/archive/' + version + '.tar.gz' + authSuffix,
headers: {
'accept': 'application/octet-stream'
},
}, self.defaultRequestOptions
))
.on('response', function(pkgRes) {
Expand DownExpand Up@@ -730,7 +735,7 @@ GithubLocation.prototype = {
checkReleases: function(repo, version) {
// NB cache this on disk with etags
var reqOptions = extend({
uri: this.apiRemoteString + 'repos/' + repo + '/releases',
uri: this.apiRemoteString + 'repos/' + repo + '/releases' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
91 changes: 48 additions & 43 deletions github.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,10 +33,11 @@ catch(e) {}
var execGit = require('./exec-git');

function createRemoteStrings(auth, hostname) {
var authString = auth ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
var authString = auth.username ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
hostname = hostname || 'github.com';

this.remoteString = 'https://' + authString + hostname + '/';
this.authSuffix = auth.token ? '?access_token=' + auth.token : '';

if (hostname == 'github.com')
this.apiRemoteString = 'https://' + authString + 'api.github.com/';
Expand All@@ -46,10 +47,6 @@ function createRemoteStrings(auth, hostname) {
this.apiRemoteString = 'https://' + authString + hostname + '/api/v3/';
}

// avoid storing passwords as plain text in config
function encodeCredentials(auth) {
return new Buffer(encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password)).toString('base64');
}
function decodeCredentials(str) {
var auth = new Buffer(str, 'base64').toString('ascii').split(':');

Expand DownExpand Up@@ -81,6 +78,10 @@ function readNetrc(hostname) {
}
}

function isGithubToken(token) {
return token.match(/[0-9a-f]{40}/);
}

var GithubLocation = function(options, ui) {

// ensure git is installed
Expand All@@ -98,19 +99,15 @@ var GithubLocation = function(options, ui) {
this.versionString = options.versionString + '.1';

// Give the environment precedence over options object
if(process.env.JSPM_GITHUB_AUTH_TOKEN) {
options.auth = process.env.JSPM_GITHUB_AUTH_TOKEN;
} else if (options.username && !options.auth) {
options.auth = encodeCredentials(options);
// NB deprecate old auth eventually
// delete options.username;
// delete options.password;
}
var auth = process.env.JSPM_GITHUB_AUTH_TOKEN || options.auth;

if (typeof options.auth == 'string') {
this.auth = decodeCredentials(options.auth);
}
else {
if (auth) {
if (isGithubToken(auth)) {
this.auth = { token: auth };
} else {
this.auth = decodeCredentials(auth);
}
} else {
this.auth = readNetrc(options.hostname);
}

Expand DownExpand Up@@ -148,7 +145,7 @@ var GithubLocation = function(options, ui) {

this.remote = options.remote;

createRemoteStrings.call(this, this.auth, options.hostname);
createRemoteStrings.call(this, this.auth || {}, options.hostname);
};

function clearDir(dir) {
Expand DownExpand Up@@ -199,20 +196,27 @@ function configureCredentials(config, ui) {

return Promise.resolve()
.then(function() {
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%. Ensure it has `public_repo` scope access.');
return ui.input('Enter your GitHub username');
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%.');
return ui.input('Enter your GitHub username or access token');
})
.then(function(username) {
auth.username = username;
if (auth.username)
return ui.input('Enter your GitHub password or access token', null, true);
.then(function(entered) {
if (!entered) {
return false;
} else if (isGithubToken(entered)) {
auth.token = entered;
} else {
auth.username = entered;
return ui.input('Enter your GitHub password', null, true);
}
})
.then(function(password) {
auth.password = password;
if (!auth.username)
return false;
if (password) {
auth.password = password;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again keep this code, with the prompt being Enter your GitHub username or access token as the first question, with the isGithubToken resulting in the new path (skipping password prompt), and otherwise the old path.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left this as-is (with the old code removed) since we don't need to allow this old stuff to go in.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Backwards compat should really mean the same prompts too I think.
On Sun, 12 Jun 2016 at 02:49, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Left this as-is (with the old code removed) since we don't need to allow
this old stuff to go in.


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714112,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiyrxzLDoQA_BvR-jvnJFmFE3VFUQcks5qK1eZgaJpZM4Izqxv
.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why? That means none of this can ever be deprecated or removed. We want to make sure people's existing configuration works, but why does that mean we need to support both forms forever?

That also creates a more confusing situation with the access tokens - if you use username/password you need to give public_repo, and otherwise you don't. Doesn't seem great

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Because the prompts form part of the public API.

If the PR was against the 0.17 branch for the jspm beta then we can
definitely consider doing that for 0.17. But on the 0.16 branch they should
remain as users expect now to be able to directly enter their github
username and password (which allows not having to go to the website to
create a token at all)
On Sun, 12 Jun 2016 at 02:54, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Why? That means none of this can ever be deprecated or removed. We want to
make sure people's existing configuration works, but why does that mean we
need to support both forms forever?

That also creates a more confusing situation with the access tokens - if
you use username/password you need to give public_repo, and otherwise you
don't. Doesn't seem great


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714150,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiykjKrj7oHuNSqxdXtl8EFq_VgRjXks5qK1izgaJpZM4Izqxv
.

@tamirdtamirdJun 12, 2016

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #91.


return ui.confirm('Would you like to test these credentials?', true);
if (auth.username || auth.token) {
return ui.confirm('Would you like to test these credentials?', true);
}
})
.then(function(test) {
if (!test)
Expand All@@ -224,7 +228,7 @@ function configureCredentials(config, ui) {
createRemoteStrings.call(remotes, auth, config.hostname);

return asp(request)({
uri: remotes.apiRemoteString + 'user',
uri: remotes.apiRemoteString + 'user' + remotes.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand DownExpand Up@@ -254,10 +258,10 @@ function configureCredentials(config, ui) {
.then(function(redo) {
if (redo)
return configureCredentials(config, ui);
return encodeCredentials(auth);
return auth.token;
});
else if (auth.username)
return encodeCredentials(auth);
else if (auth.token)
return auth.token;
else
return null;
});
Expand DownExpand Up@@ -328,14 +332,15 @@ GithubLocation.prototype = {
locate: function(repo) {
var self = this;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

if (repo.split('/').length !== 2)
throw "GitHub packages must be of the form `owner/repo`.";

// request the repo to check that it isn't a redirect
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo,
uri: remoteString + repo + authSuffix,
headers: {
'User-Agent': 'jspm'
},
Expand DownExpand Up@@ -433,7 +438,7 @@ GithubLocation.prototype = {
version = 'v' + version;

return asp(request)(extend({
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json',
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3.raw'
Expand DownExpand Up@@ -538,6 +543,7 @@ GithubLocation.prototype = {
var execOpt = this.execOpt;
var max_repo_size = this.max_repo_size;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

var self = this;

Expand DownExpand Up@@ -640,16 +646,12 @@ GithubLocation.prototype = {

// now that the inPipe is ready, do the request
request(extend({
uri: release.url,
uri: release.url + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
},
followRedirect: false,
auth: self.auth && {
user: self.auth.username,
pass: self.auth.password
}
}, self.defaultRequestOptions
)).on('response', function(archiveRes) {
var rateLimitResponse = checkRateLimit.call(this, archiveRes.headers);
Expand All@@ -660,7 +662,8 @@ GithubLocation.prototype = {
return reject('Bad response code ' + archiveRes.statusCode + '\n' + JSON.stringify(archiveRes.headers));

request(extend({
uri: archiveRes.headers.location, headers: {
uri: archiveRes.headers.location + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
}
Expand DownExpand Up@@ -692,8 +695,10 @@ GithubLocation.prototype = {
// Download from the git archive
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo + '/archive/' + version + '.tar.gz',
headers: { 'accept': 'application/octet-stream' }
uri: remoteString + repo + '/archive/' + version + '.tar.gz' + authSuffix,
headers: {
'accept': 'application/octet-stream'
},
}, self.defaultRequestOptions
))
.on('response', function(pkgRes) {
Expand DownExpand Up@@ -730,7 +735,7 @@ GithubLocation.prototype = {
checkReleases: function(repo, version) {
// NB cache this on disk with etags
var reqOptions = extend({
uri: this.apiRemoteString + 'repos/' + repo + '/releases',
uri: this.apiRemoteString + 'repos/' + repo + '/releases' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
91 changes: 48 additions & 43 deletions github.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,10 +33,11 @@ catch(e) {}
var execGit = require('./exec-git');

function createRemoteStrings(auth, hostname) {
var authString = auth ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
var authString = auth.username ? (encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password) + '@') : '';
hostname = hostname || 'github.com';

this.remoteString = 'https://' + authString + hostname + '/';
this.authSuffix = auth.token ? '?access_token=' + auth.token : '';

if (hostname == 'github.com')
this.apiRemoteString = 'https://' + authString + 'api.github.com/';
Expand All@@ -46,10 +47,6 @@ function createRemoteStrings(auth, hostname) {
this.apiRemoteString = 'https://' + authString + hostname + '/api/v3/';
}

// avoid storing passwords as plain text in config
function encodeCredentials(auth) {
return new Buffer(encodeURIComponent(auth.username) + ':' + encodeURIComponent(auth.password)).toString('base64');
}
function decodeCredentials(str) {
var auth = new Buffer(str, 'base64').toString('ascii').split(':');

Expand DownExpand Up@@ -81,6 +78,10 @@ function readNetrc(hostname) {
}
}

function isGithubToken(token) {
return token.match(/[0-9a-f]{40}/);
}

var GithubLocation = function(options, ui) {

// ensure git is installed
Expand All@@ -98,19 +99,15 @@ var GithubLocation = function(options, ui) {
this.versionString = options.versionString + '.1';

// Give the environment precedence over options object
if(process.env.JSPM_GITHUB_AUTH_TOKEN) {
options.auth = process.env.JSPM_GITHUB_AUTH_TOKEN;
} else if (options.username && !options.auth) {
options.auth = encodeCredentials(options);
// NB deprecate old auth eventually
// delete options.username;
// delete options.password;
}
var auth = process.env.JSPM_GITHUB_AUTH_TOKEN || options.auth;

if (typeof options.auth == 'string') {
this.auth = decodeCredentials(options.auth);
}
else {
if (auth) {
if (isGithubToken(auth)) {
this.auth = { token: auth };
} else {
this.auth = decodeCredentials(auth);
}
} else {
this.auth = readNetrc(options.hostname);
}

Expand DownExpand Up@@ -148,7 +145,7 @@ var GithubLocation = function(options, ui) {

this.remote = options.remote;

createRemoteStrings.call(this, this.auth, options.hostname);
createRemoteStrings.call(this, this.auth || {}, options.hostname);
};

function clearDir(dir) {
Expand DownExpand Up@@ -199,20 +196,27 @@ function configureCredentials(config, ui) {

return Promise.resolve()
.then(function() {
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%. Ensure it has `public_repo` scope access.');
return ui.input('Enter your GitHub username');
ui.log('info', 'If using two-factor authentication or to avoid using your password you can generate an access token at %https://' + (config.hostname || 'github.com') + '/settings/tokens%.');
return ui.input('Enter your GitHub username or access token');
})
.then(function(username) {
auth.username = username;
if (auth.username)
return ui.input('Enter your GitHub password or access token', null, true);
.then(function(entered) {
if (!entered) {
return false;
} else if (isGithubToken(entered)) {
auth.token = entered;
} else {
auth.username = entered;
return ui.input('Enter your GitHub password', null, true);
}
})
.then(function(password) {
auth.password = password;
if (!auth.username)
return false;
if (password) {
auth.password = password;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again keep this code, with the prompt being Enter your GitHub username or access token as the first question, with the isGithubToken resulting in the new path (skipping password prompt), and otherwise the old path.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left this as-is (with the old code removed) since we don't need to allow this old stuff to go in.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Backwards compat should really mean the same prompts too I think.
On Sun, 12 Jun 2016 at 02:49, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Left this as-is (with the old code removed) since we don't need to allow
this old stuff to go in.


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714112,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiyrxzLDoQA_BvR-jvnJFmFE3VFUQcks5qK1eZgaJpZM4Izqxv
.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why? That means none of this can ever be deprecated or removed. We want to make sure people's existing configuration works, but why does that mean we need to support both forms forever?

That also creates a more confusing situation with the access tokens - if you use username/password you need to give public_repo, and otherwise you don't. Doesn't seem great

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Because the prompts form part of the public API.

If the PR was against the 0.17 branch for the jspm beta then we can
definitely consider doing that for 0.17. But on the 0.16 branch they should
remain as users expect now to be able to directly enter their github
username and password (which allows not having to go to the website to
create a token at all)
On Sun, 12 Jun 2016 at 02:54, Tamir Duberstein notifications@github.com
wrote:

In github.js #90 (comment)
:

})

  • .then(function(username) {
  • auth.username = username;
  • if (auth.username)
  •  return ui.input('Enter your GitHub password or access token', null, true);
    
  • })
  • .then(function(password) {
  • auth.password = password;
  • if (!auth.username)

- return false;

  • return ui.confirm('Would you like to test these credentials?', true);

Why? That means none of this can ever be deprecated or removed. We want to
make sure people's existing configuration works, but why does that mean we
need to support both forms forever?

That also creates a more confusing situation with the access tokens - if
you use username/password you need to give public_repo, and otherwise you
don't. Doesn't seem great


You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/90/files/7e73f5e239dac1f8eca852495dc8029f82991f26#r66714150,
or mute the thread
https://github.com/notifications/unsubscribe/AAkiykjKrj7oHuNSqxdXtl8EFq_VgRjXks5qK1izgaJpZM4Izqxv
.

@tamirdtamirdJun 12, 2016

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #91.


return ui.confirm('Would you like to test these credentials?', true);
if (auth.username || auth.token) {
return ui.confirm('Would you like to test these credentials?', true);
}
})
.then(function(test) {
if (!test)
Expand All@@ -224,7 +228,7 @@ function configureCredentials(config, ui) {
createRemoteStrings.call(remotes, auth, config.hostname);

return asp(request)({
uri: remotes.apiRemoteString + 'user',
uri: remotes.apiRemoteString + 'user' + remotes.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand DownExpand Up@@ -254,10 +258,10 @@ function configureCredentials(config, ui) {
.then(function(redo) {
if (redo)
return configureCredentials(config, ui);
return encodeCredentials(auth);
return auth.token;
});
else if (auth.username)
return encodeCredentials(auth);
else if (auth.token)
return auth.token;
else
return null;
});
Expand DownExpand Up@@ -328,14 +332,15 @@ GithubLocation.prototype = {
locate: function(repo) {
var self = this;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

if (repo.split('/').length !== 2)
throw "GitHub packages must be of the form `owner/repo`.";

// request the repo to check that it isn't a redirect
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo,
uri: remoteString + repo + authSuffix,
headers: {
'User-Agent': 'jspm'
},
Expand DownExpand Up@@ -433,7 +438,7 @@ GithubLocation.prototype = {
version = 'v' + version;

return asp(request)(extend({
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json',
uri: this.apiRemoteString + 'repos/' + repo + '/contents/package.json' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3.raw'
Expand DownExpand Up@@ -538,6 +543,7 @@ GithubLocation.prototype = {
var execOpt = this.execOpt;
var max_repo_size = this.max_repo_size;
var remoteString = this.remoteString;
var authSuffix = this.authSuffix;

var self = this;

Expand DownExpand Up@@ -640,16 +646,12 @@ GithubLocation.prototype = {

// now that the inPipe is ready, do the request
request(extend({
uri: release.url,
uri: release.url + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
},
followRedirect: false,
auth: self.auth && {
user: self.auth.username,
pass: self.auth.password
}
}, self.defaultRequestOptions
)).on('response', function(archiveRes) {
var rateLimitResponse = checkRateLimit.call(this, archiveRes.headers);
Expand All@@ -660,7 +662,8 @@ GithubLocation.prototype = {
return reject('Bad response code ' + archiveRes.statusCode + '\n' + JSON.stringify(archiveRes.headers));

request(extend({
uri: archiveRes.headers.location, headers: {
uri: archiveRes.headers.location + authSuffix,
headers: {
'accept': 'application/octet-stream',
'user-agent': 'jspm'
}
Expand DownExpand Up@@ -692,8 +695,10 @@ GithubLocation.prototype = {
// Download from the git archive
return new Promise(function(resolve, reject) {
request(extend({
uri: remoteString + repo + '/archive/' + version + '.tar.gz',
headers: { 'accept': 'application/octet-stream' }
uri: remoteString + repo + '/archive/' + version + '.tar.gz' + authSuffix,
headers: {
'accept': 'application/octet-stream'
},
}, self.defaultRequestOptions
))
.on('response', function(pkgRes) {
Expand DownExpand Up@@ -730,7 +735,7 @@ GithubLocation.prototype = {
checkReleases: function(repo, version) {
// NB cache this on disk with etags
var reqOptions = extend({
uri: this.apiRemoteString + 'repos/' + repo + '/releases',
uri: this.apiRemoteString + 'repos/' + repo + '/releases' + this.authSuffix,
headers: {
'User-Agent': 'jspm',
'Accept': 'application/vnd.github.v3+json'
Expand Down