Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 16 additions & 1 deletion src/uploadReport.ts
Original file line number Diff line number Diff line change
Expand Up @@ -229,7 +229,8 @@ export type UploadOptions = {
*
* @returns {Promise<UploadResult>} Promise that resolves to an upload result object:
* - `{ status: 'success', reportUrl: string }` - Upload succeeded, includes web URL to view report
* - `{ status: 'skipped', reason: string }` - Upload was skipped (e.g., no access token)
* - `{ status: 'skipped', reason: string }` - Upload was skipped (e.g., no access token or the
* OIDC token belongs to a fork instead of the repository bound to the Flakiness project)
* - `{ status: 'failed', error: string }` - Upload failed, includes error message
*
* @throws {Error} Only throws if `options.throwOnFailure` is true and upload fails.
Expand Down Expand Up @@ -281,6 +282,11 @@ export async function uploadReport(
const uploadResult = await upload.upload();
if (!uploadResult.success) {
const errorMessage = uploadResult.message || 'Unknown upload error';
const repositoryMismatchReason = oidcRepositoryMismatchReason(errorMessage);
if (repositoryMismatchReason !== undefined) {
logger.warn(`[flakiness.io] ⚠ Skipping upload: ${repositoryMismatchReason}`);
return { status: 'skipped', reason: repositoryMismatchReason };
Comment on lines +285 to +288

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Avoid downgrading non-fork repository mismatches

When a normal base-repository job is accidentally configured with a Flakiness project bound to another repository, the server returns the same repository-mismatch message as it does for a fork. Because this check uses only that message, it now returns skipped and bypasses throwOnFailure: true, causing strict CI workflows to pass while every report remains unuploaded. Restrict the downgrade to a verifiable fork context or a server error code that specifically identifies an expected fork upload.

Useful? React with 👍 / 👎.

}
logger.error(`[flakiness.io] ✕ Failed to upload: ${errorMessage}`);
if (options?.throwOnFailure)
throw new Error(`Flakiness upload failed: ${errorMessage}`);
Expand All @@ -298,6 +304,15 @@ export async function uploadReport(
}
}

function oidcRepositoryMismatchReason(errorMessage: string): string | undefined {
const messageStart = 'OIDC token repository "';
const messageMiddle = '" does not match flakiness project repository "';
const messageStartIndex = errorMessage.indexOf(messageStart);
if (messageStartIndex === -1 || !errorMessage.includes(messageMiddle, messageStartIndex + messageStart.length))
return undefined;
return errorMessage.slice(messageStartIndex).trim();
}

class ReportUpload {
private _report: FlakinessReport.Report;
private _attachments: Attachment[];
Expand Down