| 1 | name: Inspect Cloudflare download access |
| 2 | run-name: Inspect public release manifest access |
| 3 | |
| 4 | on: |
| 5 | workflow_dispatch: |
| 6 | |
| 7 | permissions: |
| 8 | contents: read |
| 9 | |
| 10 | concurrency: |
| 11 | group: cloudflare-download-access |
| 12 | cancel-in-progress: false |
| 13 | |
| 14 | jobs: |
| 15 | inspect: |
| 16 | if: github.ref == 'refs/heads/main-v2' |
| 17 | runs-on: ubuntu-latest |
| 18 | timeout-minutes: 5 |
| 19 | steps: |
| 20 | - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 |
| 21 | with: |
| 22 | ref: ${{ github.sha }} |
| 23 | - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 |
| 24 | with: |
| 25 | node-version: "24" |
| 26 | - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7 |
| 27 | with: |
| 28 | go-version-file: desktop/go.mod |
| 29 | - name: Inspect the public manifest and its challenge policy |
| 30 | env: |
| 31 | CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} |
| 32 | run: node scripts/inspect-cloudflare-download-access.mjs |
| 33 | - name: Probe the shipped updater HTTP client |
| 34 | run: go run scripts/inspect-cloudflare-download-access.go 1.38.11 1.38.12 |
| 35 | - name: Probe the public site with headless Chromium |
| 36 | run: | |
| 37 | browser="$(command -v google-chrome || command -v google-chrome-stable || command -v chromium)" |
| 38 | for path in '?download=desktop&release-postflight=v1.38.12' 'changelog/v1.38.12/'; do |
| 39 | for profile in default updater browser; do |
| 40 | output="$(mktemp)" |
| 41 | profile_dir="$(mktemp -d)" |
| 42 | flags=() |
| 43 | case "$profile" in |
| 44 | updater) flags+=(--user-agent='Reasonix-Updater/v1.38.12 (linux/amd64; build=stable; update=stable)') ;; |
| 45 | browser) flags+=(--user-agent='Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36') ;; |
| 46 | esac |
| 47 | "$browser" --headless=new --disable-gpu --no-sandbox --virtual-time-budget=10000 \ |
| 48 | "--user-data-dir=$profile_dir" "${flags[@]}" \ |
| 49 | --dump-dom "https://reasonix.io/$path" >"$output" 2>/dev/null || true |
| 50 | node -e 'const fs=require("fs"); const body=fs.readFileSync(process.argv[1],"utf8"); console.log(JSON.stringify({kind:"chromium-site",profile:process.argv[2],path:process.argv[3],hasHydratedDesktopVersion:body.includes("data-release-version=\"desktop\">v1.38.12<"),hasDesktopAsset:body.includes("data-desktop-asset="),looksChallenged:body.includes("Just a moment...")}))' "$output" "$profile" "$path" |
| 51 | rm -rf "$output" "$profile_dir" |
| 52 | done |
| 53 | done |
| 54 |