2026-10-02 GnuCash IRC logs
01:09:46 *** fell has quit IRC
01:11:05 *** fell has joined #gnucash
01:11:05 *** ChanServ sets mode: +o fell
01:54:48 *** leighbb has quit IRC
01:55:48 *** leighbb has joined #gnucash
01:55:48 *** ChanServ sets mode: +v leighbb
02:49:54 *** skyenet has quit IRC
03:29:10 *** leighbb has quit IRC
03:34:32 *** leighbb has joined #gnucash
03:34:32 *** ChanServ sets mode: +v leighbb
03:37:41 *** skyenet has joined #gnucash
03:37:41 *** ChanServ sets mode: +v skyenet
04:19:05 *** leighbb has quit IRC
05:21:03 *** rocartur has joined #gnucash
06:37:05 *** leighbb has joined #gnucash
06:37:05 *** ChanServ sets mode: +v leighbb
07:56:07 *** fell has quit IRC
07:57:26 *** fell has joined #gnucash
07:57:27 *** ChanServ sets mode: +o fell
09:25:34 <warlord> jralls, started looking into the port-knocker. Why do you need to authenticate to pull the artifact? And with what would code authenticate? Code does not have the gh client, so it would need to be done manually.
09:25:51 <warlord> Does the token need to be acquired once oob, or regularly by the script?
09:26:50 <warlord> (here I thought it was going to be "here, install this script that runs when pinged on port XXX". Although now I'm thinking it might be better to be a CGI POST.
13:07:15 *** rocartur has quit IRC
17:14:18 <jralls> warlord, you need to authenticate because Github says so and it's their site. You might consider installing gh on code, it makes it a bit easer, but you can also authenticate by inserting the appropriate headers into a curl request.
17:16:57 <jralls> The docs on Personal Access tokens: https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens
17:17:48 <jralls> Instructions for accomplishing the download: https://docs.github.com/en/actions/how-tos/manage-workflow-runs/download-workflow-artifacts Note that it says at the top that people must be signed in.
17:27:11 <jralls> warlord, we could instead have the workflow push the setup.exe to code with rsync or sftp. I'd think that would expose a somewhat larger attack surface that you would prefer to avoid.
17:32:30 <warlord> jralls, yeah -- i'd rather not provide that mechanism to github.
17:32:42 <warlord> I did look for the gh program but didn't see any package that provided it.
17:37:37 <jralls> https://cli.github.com/packages/rpm/gh-cli.repo
17:38:08 <jralls> The fedora package is called gh, as in `dnf install dh`, but IIRC code is on an ancient RHEL that probably predates github-cli. There's supposed to be a Github repo with rpms at that url (my irc client just did something weird with paste).
17:38:27 <jralls> s/dh/gh/
17:41:52 <warlord> I suspect code is too old.
17:45:09 <warlord> Oooh, there IS one! it installed.
17:45:13 *** AdrienM has quit IRC
17:46:06 <warlord> So now the question is how to get code to authenticate. There IS a gnucash-git GH user account...
17:46:17 *** AdrienM has joined #gnucash
17:46:18 *** ChanServ sets mode: +v AdrienM
17:52:43 <jralls> Or you can your own gh account. To authenticate you make a fine grained personal access token and set GH_TOKEN to it, then you can run `gh run download` like I explained in the email.
17:53:48 <warlord> for 'gh run download', is GH_TOKEN an env var?
17:55:32 <jralls> Yes.
18:16:02 <warlord> I presume the key has no password on it?
18:22:09 <warlord> jralls, don't I need to tell gh run download the path/package/project for the artifact?
18:26:02 <warlord> Or is that what -R builds/win32/future does?
18:36:00 <jralls> No, that's what <decrypted-message> does, except that you don't (right now) want the whole thing, just the run-id part, but I can easily change that in the workflow to just send the run-id. -R tells it where to put the file.
18:38:02 <jralls> And yes, the token doesn't have a password. That's why the github docs bang on about guarding it like you would. a password.
19:41:54 <warlord> That's not what the help says:
19:41:55 <warlord> -R, --repo [HOST/]OWNER/REPO Select another repository using the [HOST/]OWNER/REPO format
19:42:13 <warlord> Target directory is -D:
19:42:14 <warlord> -D, --dir string The directory to download artifacts into (default ".")
19:42:41 <warlord> jralls, I was asking about a passphrase on the gpg private key
20:07:26 <warlord> jralls, okay, I requested a token, but you need to approve it.
20:07:37 <warlord> (i am not an org owner)
23:10:00 *** jonakeys has quit IRC
23:10:08 *** jonakeys has joined #gnucash