From 50edf37a84a696846e9c0fe953da120a07dca282 Mon Sep 17 00:00:00 2001 From: Artem Zakharchenko Date: Sun, 27 Oct 2024 14:47:16 +0100 Subject: [PATCH] chore: use `actions-cool/check-user-permission` for permissions check --- .github/workflows/release-preview.yml | 22 +++++++++++++++++++--- 1 file changed, 19 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release-preview.yml b/.github/workflows/release-preview.yml index 16aa9e5c5..6fa1d8dc8 100644 --- a/.github/workflows/release-preview.yml +++ b/.github/workflows/release-preview.yml @@ -6,10 +6,26 @@ on: workflow_dispatch: jobs: + check: + # Trigger the permissions check whenever someone approves a pull request. + # They must have the write permissions to the repo in order to + # trigger preview package publishing. + if: github.event.review.state == 'approved' + runs-on: ubuntu-latest + outputs: + has-permissions: ${{ steps.checkPermissions.outputs.require-result }} + steps: + - name: Check permissions + id: checkPermissions + uses: actions-cool/check-user-permission@v2 + with: + require: 'write' + preview: - # Publish previews only for approved pull requests. - # The reviewer must have push persmissions to trigger this job. - if: github.event.review.state == 'approved' && github.event.review.user.permissions.push == true + # The approving user must pass the permissions check + # to trigger the preview publish. + needs: check + if: needs.check.outputs.has-permissions == 'true' runs-on: macos-latest steps: - name: Checkout