FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Job token authentication fails · Issue #1620 · python-gitlab/python-gitlab · GitHub

Repository navigation

Job token authentication fails #1620

Description

Description of the problem, including code/CLI snippet

The following python3 snippet fails running under Gitlab 13.12.5-ee CI pipeline:

import os, gitlab
gl = gitlab.Gitlab(os.environ['CI_SERVER_URL'], job_token=os.environ['CI_JOB_TOKEN'], user_agent='Whatever/custom-name')
gl.auth()

It's using python-gitlab v2.10.1 and it fails with:

Traceback (most recent call last):
  File "/builds/CbQEQmZ2/0/whatever/tools/project_name/./app.py", line 3, in <module>
    gl.auth()
  File "/usr/local/lib/python3.10/site-packages/gitlab/client.py", line 257, in auth
    self.user = self._objects.CurrentUserManager(self).get()
  File "/usr/local/lib/python3.10/site-packages/gitlab/exceptions.py", line 304, in wrapped_f
    return f(*args, **kwargs)
  File "/usr/local/lib/python3.10/site-packages/gitlab/mixins.py", line 146, in get
    server_data = self.gitlab.http_get(self.path, **kwargs)
  File "/usr/local/lib/python3.10/site-packages/gitlab/client.py", line 662, in http_get
    result = self.http_request(
  File "/usr/local/lib/python3.10/site-packages/gitlab/client.py", line 622, in http_request
    raise gitlab.exceptions.GitlabAuthenticationError(
gitlab.exceptions.GitlabAuthenticationError: 401: 401 Unauthorized

The .gitlab-ci.yml config is as follows:

stages:
  - run

run:
  stage: run
  rules:
    - if: '$CI_COMMIT_BRANCH == "master" && $CI_PIPELINE_SOURCE == "web"'
    - if: '$CI_COMMIT_BRANCH == "master" && $CI_PIPELINE_SOURCE == "schedule"'
  image: python:alpine
  before_script:
    - pip3 install -r requirements.txt
  script:
    - python3 app.py # This is where the snippet lives

Expected Behavior

As the documentation says, the following code should be valid:

import gitlab
# job token authentication (to be used in CI)
import os
gl = gitlab.Gitlab('http://10.0.0.1', job_token=os.environ['CI_JOB_TOKEN'])
# make an API request to create the gl.user object. This is mandatory if you
# use the username/password authentication.
gl.auth()

Actual Behavior

The gl.auth() method fails with a GitlabAuthenticationError exception.

Specifications

  • python-gitlab version: v2.10.1
  • API version you are using (v3/v4): v4
  • Gitlab server version (or gitlab.com): 13.12.5-ee

Activity

  1. nejch commented on Oct 6, 2021

    Member

    Hi @axl89, the documentation might not be very clear on this, but the CI_JOB_TOKEN is very limited in what endpoints it can really reach, so I think this is actually expected behavior. gl.auth() calls the /user endpoint to get the current user's details, and this is not among the endpoints the job token has access to - see https://docs.gitlab.com/ee/ci/jobs/ci_job_token.html.

    I'm not sure how much we should duplicate the upstream documentation on this - but if you'd like to add a small addition/note with the link above, PR's are very welcome! :)

    In any case, if you remove the gl.auth() (it's not needed) call you should be able to use the job token in your script. But keep in mind the limitations - maybe what you're trying to do later in the script is also not available via the job token.

  2. axl89 commented on Oct 6, 2021

    ContributorAuthor

    Hi @nejch , thank you for reaching out! 😄

    As you mentioned, the limit hit us in the face pretty soon. The snippet:

    import os, gitlab
    
    def get_projects_from_group(gl, group_id):
        group = gl.groups.get(group_id, include_subgroups=True, lazy=True)
        return group.projects.list(all=True)
    
    gl = gitlab.Gitlab(os.environ['CI_SERVER_URL'], job_token=os.environ['CI_JOB_TOKEN'], user_agent='Whatever/custom-name')
    target_projects = get_projects_from_group(gl,69)

    breaks with:

    Traceback (most recent call last):
      File "/builds/CbQEQmZ2/0/whatever/tools/project/./app.py", line 7, in <module>
        target_projects = get_projects_from_group(gl,target_group_id)
      File "/builds/CbQEQmZ2/0/whatever/tools/project/./app.py", line 5, in get_projects_from_group
        return group.projects.list(all=True)
      File "/usr/local/lib/python3.10/site-packages/gitlab/exceptions.py", line 306, in wrapped_f
        raise error(e.error_message, e.response_code, e.response_body) from e
    gitlab.exceptions.GitlabListError: 404: 404 Group Not Found
    

    , so I guess we should continue using the personal access tokens 😞

    I'll submit a PR later if I'm a bit free to clarify the docs. Thanks again!

  3. added a commit that references this issue on Oct 7, 2021
  4. nejch commented on Oct 9, 2021

    Member

    Closed by #1624.

  5. locked as resolved and limited conversation to collaborators on Oct 10, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions


      Back | FazBrowse Home | New Git URL