feat(setup-npm-registry): browser-assisted classic PAT creation

When no token is found via --token/env/gh CLI, the script now opens
github.com/settings/tokens/new pre-scoped to read:packages with clear
instructions on Note/Expiration/Scopes, falling back to printing the
URL when a browser can't be launched (SSH, containers, CI). Add
--no-open to skip the launch attempt outright.

Also document the flow in README (new 'Generating a GitHub token'
section) and QUICKSTART troubleshooting, and add a hermetic test
covering the --no-open + piped-token path.
This commit is contained in:
2026-09-10 01:44:28 +02:00
parent 66219525ba
commit cf13066baa
5 changed files with 108 additions and 15 deletions
+21
View File
@@ -95,6 +95,27 @@ describe('setup-npm-registry script', () => {
assert.match(content, /\/\/example\.test\/:_authToken=fake-token/);
});
test('--no-open prints the classic-PAT URL and accepts a pasted token via stdin', () => {
const npmrc = tempNpmrcPath();
const r = execFileSync(process.execPath, [
SCRIPT, '--no-open', '--skip-verify', `--npmrc=${npmrc}`,
], {
encoding: 'utf8',
input: 'ghp_pastedtoken1234\n',
env: {
...process.env,
NPM_REGISTRY_TOKEN: '',
GITHUB_TOKEN: '',
GH_TOKEN: '',
PATH: '/nonexistent', // hide `gh` so gh-CLI discovery can't short-circuit the prompt
},
});
assert.match(r, /github\.com\/settings\/tokens\/new\?scopes=read%3Apackages/);
assert.match(r, /--no-open.*skipping automatic browser launch/);
const content = readFileSync(npmrc, 'utf8');
assert.match(content, /_authToken=ghp_pastedtoken1234/);
});
test('fails cleanly with --yes and no token available anywhere', () => {
const npmrc = tempNpmrcPath();
const r = setup(['--yes', `--npmrc=${npmrc}`], {