Skip to content

WEB-1194: Read releases from private repositories with a token (1.4.0) - #34

Merged
miguelcolmenares merged 4 commits into
mainfrom
feature/WEB-1194-updater-private-releases
Sep 25, 2026
Merged

miguelcolmenares merged 4 commits into
mainfrom
feature/WEB-1194-updater-private-releases

Conversation

@miguelcolmenares

Copy link
Copy Markdown
Member

Summary

wp-github-updater can now read the releases of a private GitHub repository with a token, and keeps working anonymously for public ones. Phase 1 of WEB-1194 (making the SilverAssist plugin repositories private without breaking updates on the sites). Once this ships, the plugins bundle it, the sites get the token, and only then the repositories go private.

Changes

  • Token. New token_constant option (default SILVER_GITHUB_TOKEN) and UpdaterConfig::getGithubToken(): a PHP constant first, then an environment variable, trimmed, null when empty. Never read from the database.
  • Requests. Authorization: Bearer is sent to api.github.com only, never to another host.
  • Download. With a token the package is the asset API URL. The download is done in two steps: the first request carries the token and stops at GitHub's redirect (redirection => 0), the second goes to the signed storage URL without the token. A redirect that is not https is refused.
  • Diagnostics. A distinct log message for 401, 403 and 404, with and without a token, naming the constant to check. The token is never logged and a failed version lookup is not cached, so a site that stops updating can be diagnosed from its PHP log.
  • PHPStan. Fixes the 29 level 8 errors and the stale ignoreErrors pattern, so composer check passes again (separate commit, no behaviour changes apart from two small hardenings listed in the CHANGELOG).
  • Docs. New "Private Repositories" README section, token_constant option, 1.4.0 CHANGELOG, integration guide example. The "public GitHub releases" wording is gone, and the README requires_php default is corrected (8.2).

Tests

Nothing from WordPress core is mocked in the new tests. They run on the real WordPress Test Suite (WP_UnitTestCase) and intercept requests with WordPress' own pre_http_request filter.

  • tests/WordPress/UpdaterPrivateReleasesTest.php: 12 tests (headers, asset URL, redirect without the token, refused insecure redirect, 401/403/404 messages, token never logged, failures not cached).
  • tests/Unit/UpdaterConfigTest.php: 7 tests for the token lookup (constant, environment, precedence, trimming).
  • tests/WordPress/PrivateRepoLiveTest.php: opt-in, skipped unless WPGU_LIVE_REPO, WPGU_LIVE_VERSION and SILVER_GITHUB_TOKEN are set.

Verification

  • PHPCS 0 errors, PHPStan level 8 0 errors (was 29).
  • Mock mode (no WordPress suite): 52 tests pass. Real WordPress suite: 80 tests pass, 3 skipped (the live ones).
  • Live run against a real private repository with a release and a ZIP asset: the latest version is read with the token, the asset is downloaded through GitHub's signed redirect and is a valid ZIP, and without the token the repository is unreachable and the log explains why.
  • Mutation check: sending the token to every host, ignoring the asset API URL, or following redirects automatically each make the expected tests fail.

Notes

  • No version field to bump (the version comes from the tag). Release v1.4.0 follows the merge.
  • The repository CI only runs the tests on a tag; there is no pull request workflow for tests, PHPCS or PHPStan. That is why the PHPStan errors went unnoticed and is worth a follow-up.
  • The existing Unit and Integration tests still use tests/wordpress-mocks.php. Migrating them to the real suite is a separate change.

- Type the array parameters and properties (array<string, mixed>)
- Narrow the update_plugins transient and guard a failed version lookup in checkForUpdate and pluginInfo
- Keep the original text when a Markdown regex fails, instead of passing null on
- Drop the stream and filename defaults from the download request and handle a missing URL path in the temp file name
- Remove the ignoreErrors pattern that no longer matched anything (WEB-1194)
- Add the token_constant option (default SILVER_GITHUB_TOKEN) and UpdaterConfig::getGithubToken(): a PHP constant first, then an environment variable, never the database
- Send Authorization: Bearer to api.github.com only, never to another host
- Use the asset API URL when a token exists and download in two steps: the first request carries the token and stops at the redirect, the second goes to the signed storage URL without it
- Log a distinct message for 401, 403 and 404 with and without a token, and never log the token; failed lookups are not cached
- Tests run on the real WordPress Test Suite with the pre_http_request filter, plus an opt-in live test against a private repository (WEB-1194)
- Add a Private Repositories README section (token setup, how it works, log messages, live test) and the token_constant option
- Add the 1.4.0 CHANGELOG entry and a private repository example to the integration guide
- Stop describing the updater as public-only in the README and the package description, and correct the requires_php default (WEB-1194)
- Add ci.yml: PHPCS, PHPStan and composer validate, PHPUnit on the real
  WordPress Test Suite (PHP 8.2, 8.3, 8.4) and standalone unit tests
- Pass COMPOSER_AUTH to composer install in ci.yml and create-release.yml
- Raise the PHPStan memory limit so composer phpstan does not crash
@miguelcolmenares
miguelcolmenares force-pushed the feature/WEB-1194-updater-private-releases branch from d468bc8 to 3f813e5 Compare September 25, 2026 14:20
@miguelcolmenares
miguelcolmenares merged commit e8f250a into main Sep 25, 2026
9 checks passed
@miguelcolmenares
miguelcolmenares deleted the feature/WEB-1194-updater-private-releases branch September 25, 2026 14:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant