Files
shields/services/github/github-auth-service.js
Paul Melnikow e1ac63d3be Finish removing server-secrets.js (#5664)
I’ve tested locally that setting `gh_token` still conditionally enables `ConditionalGithubAuthV3Service`.

Closes #3393
2020-10-07 17:29:03 -04:00

97 lines
2.9 KiB
JavaScript

'use strict'
const gql = require('graphql-tag')
const { mergeQueries } = require('../../core/base-service/graphql')
const { BaseGraphqlService, BaseJsonService } = require('..')
function createRequestFetcher(context, config) {
const { sendAndCacheRequestWithCallbacks, githubApiProvider } = context
return async (url, options) =>
githubApiProvider.requestAsPromise(
sendAndCacheRequestWithCallbacks,
url,
options
)
}
class GithubAuthV3Service extends BaseJsonService {
constructor(context, config) {
super(context, config)
this._requestFetcher = createRequestFetcher(context, config)
this.staticAuthConfigured = true
}
}
// Use Github auth, but only when static auth is configured. By using this
// class, in production it will behave like GithubAuthV3Service, and in self-
// hosting (i.e. with a configured token) like BaseJsonService. This is
// useful when consuming GitHub endpoints which are not rate-limited: it
// avoids wasting API quota on them in production.
class ConditionalGithubAuthV3Service extends BaseJsonService {
constructor(context, config) {
super(context, config)
if (context.githubApiProvider.globalToken) {
this._requestFetcher = createRequestFetcher(context, config)
this.staticAuthConfigured = true
} else {
this.staticAuthConfigured = false
}
}
}
class GithubAuthV4Service extends BaseGraphqlService {
constructor(context, config) {
super(context, config)
this._requestFetcher = createRequestFetcher(context, config)
this.staticAuthConfigured = true
}
async _requestGraphql(attrs) {
const url = `/graphql`
/*
The Github v4 API requires us to query the rateLimit object to return
rate limit info in the query body instead of the headers:
https://developer.github.com/v4/guides/resource-limitations/#returning-a-calls-rate-limit-status
This appends the relevant rateLimit query clause to each
call to the GH v4 API so we can keep track of token usage.
*/
const query = mergeQueries(
attrs.query,
gql`
query {
rateLimit {
limit
cost
remaining
resetAt
}
}
`
)
return super._requestGraphql({ ...attrs, ...{ url, query } })
}
}
/*
Choosing between the Github V3 and V4 APIs when creating a new badge:
With the V3 API, one request = one point off the usage limit.
With the V4 API one request may be many points off the usage limit depending
on the query (but will be a minimum of one).
https://developer.github.com/v4/guides/resource-limitations/#calculating-nodes-in-a-call
If we can save ourselves some usage limit it may be worth going with a
REST (V3) call over a graphql query.
All other things being equal, a graphql query will almost always be a smaller
number of bytes over the wire and a smaller/simpler object to parse.
*/
module.exports = {
GithubAuthV3Service,
ConditionalGithubAuthV3Service,
GithubAuthV4Service,
}