Sitelet https://web.archive.org/web/20200522162124/https://github.com/octokit/rest.js/issues/881
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

`octokit.repos.getArchiveLink()` not working in browser #881

Open
gr2m opened this issue May 22, 2018 · 11 comments
Open

`octokit.repos.getArchiveLink()` not working in browser #881

gr2m opened this issue May 22, 2018 · 11 comments
Projects

Comments

@gr2m
Copy link
Member

@gr2m gr2m commented May 22, 2018 •

this is a follow up for #736 about .repos.getArchiveLink

One way to handle it is to add a new flag like "hasRedirectResponse" in lib/routes.json. If it is set then the method should be HEAD and the method should return with the value of the Location response header. Note that it’s currently not accessible using fetch, the GitHub API needs to return an additional header, see https://stackoverflow.com/a/38975988/206879

Another alternative would be only replace repos.getArchiveLink with repos.getArchive and then add to the documentation that if the user does not want to follow the redirect, they have to set method: 'HEAD' in the request options and then read out the URL from the response’s headers location

@sgvictorino
Copy link
Contributor

@sgvictorino sgvictorino commented Jun 13, 2018

@gr2m could you please provide an example of the proposed documentation for repos.getArchive? I'm having trouble getting the response into a file myself, and that's holding up my testing of some aspects of #914.

@gr2m
Copy link
Member Author

@gr2m gr2m commented Jun 13, 2018

Unfortunately this is currently blocked by GitHub’s APIs which doesn’t expose the location header correctly. Once that is resolved this code should work

client.repos.getArchiveLink({
  method: 'HEAD',
  owner: 'octocat',
  repo: 'Hello-World',
  archive_format: 'tarball',
  ref: 'master'
})

  .then(response => {
    console.log(response.headers.location)
  })

Sorry for all the trouble, it’s all a bit more complicated with the JavaScript Octokit. I’ll follow up with the Hubbers on the state of that

If you like you can create a separate issue describing what exactly you are trying to achieve and I’ll help you to find the best workaround for now? Also let me know if your code is run in Node.js or Browser

@gr2m
Copy link
Member Author

@gr2m gr2m commented Oct 31, 2018

It looks like GitHub just exposed the location header, but I still cannot get the location header:

fetch('https://api.github.com/repos/octocat/Hello-World/tarball/master', {method: 'HEAD', redirect: 'manual'})

  .then(response => {
    console.log(response.headers.get('location'))
  })

I’m now pretty sure that it’s not possible to access headers from a redirect response due to security concerns.

However the above code works with node-fetch, so it should work in Node

@gr2m
Copy link
Member Author

@gr2m gr2m commented Nov 20, 2018

what is possible is this:

fetch('https://api.github.com/repos/octocat/Hello-World/tarball/master', {method: 'HEAD'})

  .then(response => {
    console.log(response.url)
  })

But the CORS setting of the codeland.github.com does not allow for that at this point, I contacted the API team

@gr2m
Copy link
Member Author

@gr2m gr2m commented Dec 7, 2018

I got a response from GitHub support that they are looking into updating the CORS setting for codeland.github.com

@zeke
Copy link
Member

@zeke zeke commented Jan 20, 2019

I just bumped into this today. Here's how I'm working around it for now on a private repo:

const got = require('got')
const { headers } = await got('https://api.github.com/repos/github/some-private-repo/tarball', {
  json: true,
  followRedirect: false,
  headers: {
    accept: 'application/vnd.github.v3+json',
    authorization: `token ${process.env.GITHUB_TOKEN}`
  }
})

console.log(headers.location)
// https://codeload.github.com/github/some-private-repo/legacy.tar.gz/master?token=XXX
@gr2m
Copy link
Member Author

@gr2m gr2m commented Jan 20, 2019

You shouldn’t need a workaround for Node, it looks like there is actually a bug, we should set response.url. Here is a test case: https://runkit.com/gr2m/octokit-rest-js-881/1.0.0

RunKit Notebook Remove
Environment details
  • Node 10.15.0
  • node-fetch: 2.3.0
  • @octokit/rest: 16.10.0

Getting the URL for endpoints with 3xx redirects: octokit/rest.js#881. Demo to show that node-fetch works in Node.

const fetch = require('node-fetch')

await fetch('https://api.github.com/repos/octocat/Hello-World/tarball/master', {method: 'HEAD'})

  .then(response => {
    console.log(`URL: ${response.url}`)
  })

Result
But currently does not work when using @octokit/rest

const octokit = require('@octokit/rest')()

await octokit.repos.getArchiveLink({
  method: 'HEAD',
  owner: 'octocat',
  repo: 'Hello-World',
  archive_format: 'tarball',
  ref: 'master'
})

  .then(response => {
    console.log(`URL: ${response.url}`)
  })

Result

I’ll look into it

gr2m added a commit that referenced this issue Jan 20, 2019
gr2m added a commit that referenced this issue Jan 20, 2019
@gr2m gr2m added bug and removed feature labels Jan 20, 2019
@gr2m gr2m changed the title Getting the URL for endpoints with 3xx redirects `octokit.repos.getArchiveLink()` not working in browser Jan 20, 2019
@gr2m
Copy link
Member Author

@gr2m gr2m commented Jan 20, 2019

@zeke it now works in Node

https://runkit.com/gr2m/octokit-rest-js-881/1.1.0

RunKit Notebook Remove
Environment details
  • Node 10.15.0
  • node-fetch: 2.3.0
  • @octokit/rest@16.10.0: false
  • @octokit/rest@16.11.0: false

Getting the URL for endpoints with 3xx redirects: octokit/rest.js#881. Demo to show that node-fetch works in Node.

const fetch = require('node-fetch')

await fetch('https://api.github.com/repos/octocat/Hello-World/tarball/master', {method: 'HEAD'})

  .then(response => {
    console.log(`URL: ${response.url}`)
  })

Result
But currently did not work when using @octokit/rest < v16.11.0

const octokit16100 = require('@octokit/rest@16.10.0')()

await octokit16100.repos.getArchiveLink({
  method: 'HEAD',
  owner: 'octocat',
  repo: 'Hello-World',
  archive_format: 'tarball',
  ref: 'master'
})

  .then(response => {
    console.log(`URL: ${response.url}`)
  })

Result
But it was resolved with v16.11.0

const octokit16110 = require('@octokit/rest@16.11.0')()

await octokit16110.repos.getArchiveLink({
  method: 'HEAD',
  owner: 'octocat',
  repo: 'Hello-World',
  archive_format: 'tarball',
  ref: 'master'
})

  .then(response => {
    console.log(`URL: ${response.url}`)
  })

Result

@cdibbs
Copy link

@cdibbs cdibbs commented Mar 31, 2019

I got a response from GitHub support that they are looking into updating the CORS setting for codeland.github.com

Any word from them on this? I bumped into this, today, while exploring an idea.

@gr2m
Copy link
Member Author

@gr2m gr2m commented Mar 31, 2019

No update I’m afraid.

What’s your use case? Make sure to contact support and ask them about it. The more people ask about it, the more likely someone will look into it. Reference this issue :)

@cdibbs
Copy link

@cdibbs cdibbs commented Mar 31, 2019

What’s your use case?

I am hoping to implement a simple SPA that would allow an individual user to fetch small repos that the SPA would then manipulate prior to user downloading them.

Make sure to contact support and ask them about it.

Done. Thanks for the suggestion. :-)

@gr2m gr2m removed this from the v17.0.0 - maintenance release milestone Jan 19, 2020
@gr2m gr2m added this to Blocked in JS May 5, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
JS
  
Blocked (by GitHub APIs)
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
4 participants
You can’t perform that action at this time.