From 45abff1dc07ff6dbf87b253e8410a03fd8b83f29 Mon Sep 17 00:00:00 2001 From: Shane B Date: Sun, 9 Aug 2026 21:17:08 +0200 Subject: [PATCH] Fix the same release-token bug in the Android workflow build-release.yml had the identical wiring the exporter workflow did: the PAT passed to softprops/action-gh-release@v2 as a GITHUB_TOKEN environment variable. The action's `token` input defaults to ${{ github.token }}, and its docs say "a non-empty explicit token overrides GITHUB_TOKEN" - so the default is always non-empty and the env var is ignored. It authenticates as the built-in token, which is read-only here, and fails with 403 after the APK has been built and signed. #54 fixed this for the exporter because that was the release being cut. This workflow was never re-run, so it has been sitting on the same fault - and the next Android release would have failed at the last step, after the signing, in exactly the same way. Token moved into `with:`, and contents: write granted to the job so an unset or expired PAT degrades to a working upload rather than a 403. Checked the other workflows: update-contributors.yml also sets GITHUB_TOKEN as an environment variable, but that one is the built-in token being handed to scripts/fetch_contributors.py, which reads it from the environment. Not the same thing, and correct as written. Co-Authored-By: Claude Opus 5 --- .github/workflows/build-release.yml | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build-release.yml b/.github/workflows/build-release.yml index c6cd849f..173812c9 100644 --- a/.github/workflows/build-release.yml +++ b/.github/workflows/build-release.yml @@ -16,6 +16,12 @@ jobs: environment: 'Android Build Release' runs-on: ubuntu-latest + # The repository default is read-only, which is what turns a token that never arrives into + # a 403 at the very last step. Granting it here means the upload still works if the PAT is + # ever unset or expires - the action treats an empty token as unset and falls back to this. + permissions: + contents: write + # Only run this for 'android-app-v' tags! if: | github.event_name == 'release' @@ -150,14 +156,20 @@ jobs: name: ${{ env.date_today }} - ${{ env.app_name }} - ${{ env.repository_name }} - APK(s) release generated path: ${{ env.main_project_module }}/build/outputs/apk/release/ + # The token goes in `with:`, not `env:`. This action's `token` input defaults to + # ${{ github.token }}, and its own docs say "a non-empty explicit token overrides + # GITHUB_TOKEN" - so the default is always non-empty and an env var is ignored entirely. + # It then authenticates as the built-in token, whose contents permission is read-only + # here, and fails with 403 "Resource not accessible by integration" after the APK has + # already been built and signed. That is exactly how the 1.0.5 exporter release went out + # with no assets attached; this workflow had the same wiring and was never re-run. - name: Upload APK Release Asset to GitHub Release uses: softprops/action-gh-release@v2 if: github.event_name == 'release' with: files: ${{ env.main_project_module }}/build/outputs/apk/release/${{ env.app_name }}-${{ steps.extract_version.outputs.APP_VERSION }}.apk name: ${{ env.app_name }} Android App ${{ steps.extract_version.outputs.APP_VERSION }} - env: - GITHUB_TOKEN: ${{ secrets.ANDROID_BUILD_RELEASE_GITHUB_TOKEN }} + token: ${{ secrets.ANDROID_BUILD_RELEASE_GITHUB_TOKEN }} # Noted For Output [main_project_module]/build/outputs/bundle/release/ # - name: Upload AAB (App Bundle) Release - ${{ env.repository_name }}