Conversation
In a GitHub Actions job granted `id-token: write`, `vp run` now requests a GitHub OIDC token for the remote cache endpoint before the first upload and sends it as `Authorization: Bearer <token>` on `/store`. Fetches and downloads stay anonymous, and the runner's request token goes only to GitHub's token endpoint. The audience is the endpoint without its query, fragment, userinfo, or trailing slash. The token is kept in memory per endpoint and reused until it expires within 60 seconds; concurrent uploads share one token request. If the token request fails, or `/store` responds with 401 or 403, uploads to that endpoint stop for the rest of the run, and every skipped upload reports the same reason, so the summary shows one warning. A 401 from a GitHub Actions job without the OIDC variables adds the cause "grant `id-token: write` to this job". Without the variables elsewhere, uploads are anonymous as before. The OIDC variables are still passed through to tasks, unlike the RFC proposes, so npm Trusted Publishing keeps working. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
… client Keep the token state on `Client` instead of mirroring `StoreAuth` in an internal enum, merge `OidcTokenError` variants that only differ in wording, read only the JWT payload, and fold overlapping tests together. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
fspy benchmarklinuxmacoswindows |
wan9chi
marked this pull request as draft
September 28, 2026 08:10
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
The self-hosted Cloudflare Worker from #718 accepts
/storeonly with a GitHub Actions OIDC token for the namespace, butvp runnever sendsAuthorization. #718's e2e wrapper hides this by injecting a signed token itself. With this change,vp runrequests the token itself in the job, so publishing to the Worker only needspermissions: id-token: writeandVP_REMOTE_CACHE=read-write, with no token to configure. This follows RFC #716, section 5. Once this lands, #718's e2e wrapper can serve a fake token endpoint instead of injecting its own token.Changes
vt_remote_cache:Client::newtakes aStoreAuth:Anonymous,GithubOidc(the job'sACTIONS_ID_TOKEN_REQUEST_URLandACTIONS_ID_TOKEN_REQUEST_TOKEN), orGithubActionsWithoutOidc.Authorization: Bearer <token>on/storeonly. Fetches and downloads stay anonymous, and the request token goes only to GitHub's token endpoint.expwithout verifying it. Concurrent stores share one token request. A failed token request is kept and returned for later stores.Debugleaves out the tokens and the endpoint.GithubActionsWithoutOidc, a 401 keeps the messageHTTP status 401and gets the cause "grantid-token: writeto this job".vt:Session::cache()chooses theStoreAuthfrom the session envs. Once an upload is unauthorized (no token, or a 401 or 403 response), uploads to that endpoint stop for the rest of the run, and later ones return the same error without a request, so the summary shows one warning. The task's exit status doesn't change.vtt oidc-remote-cachehelper that fakes the token endpoint and a store that checks the bearer token. Neither needs Node, so they run on all platforms.vt_remote_cacheREADME, thecache.remotedoc comments, and the remote caching changelog entry.