From 1fe455e8eb30f952851e8c0b799dfa8f84b06a8c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Eray=20Ayd=C4=B1n?= Date: Thu, 24 Sep 2026 22:53:15 +0300 Subject: [PATCH] chore: update schema URL and harden sync script Update the OpenAPI schema URL. Use an `env bash` shebang so the script picks up bash from PATH rather than whatever sits at /bin/bash. Resolve paths relative to the repository root, so the script no longer writes into whatever directory it is invoked from. Collect the curl flags into `CURL_OPTS`, gated on `TRACE` and `ACTIONS_STEP_DEBUG` so runs can be made verbose, and add hardening: refuse redirects that leave https, and bound connect and transfer time so a stalled download cannot hang CI or a local run. Log the download. Inline the base URL into `schemaUrl`. Related-Task: INTER-2472 --- sync.sh | 19 +++++++++++++++---- 1 file changed, 15 insertions(+), 4 deletions(-) diff --git a/sync.sh b/sync.sh index b9b79a1e..70be76d3 100755 --- a/sync.sh +++ b/sync.sh @@ -1,11 +1,22 @@ -#!/bin/bash +#!/usr/bin/env bash set -euo pipefail -defaultBaseUrl="https://fingerprintjs.github.io/fingerprint-pro-server-api-openapi" -schemaUrl="${1:-$defaultBaseUrl/schemas/fingerprint-server-api-compact.yaml}" +# Resolve paths relative to the repository root, so the script can be run from +# any working directory. +cd "$(dirname "${BASH_SOURCE[0]}")" + +schemaUrl="${1:-https://fingerprintjs.github.io/openapi/schemas/fingerprint-server-api-compact.yaml}" + +CURL_OPTS=(-fSL --retry 3 --proto-redir '=https' --connect-timeout 10 --max-time 300) +if [[ "${TRACE:-}" != "true" && "${ACTIONS_STEP_DEBUG:-}" != "true" ]]; then + CURL_OPTS+=(-s) +fi mkdir -p ./res -curl -fSL --retry 3 -o ./res/fingerprint-server-api.yaml "$schemaUrl" +echo "Downloading $schemaUrl" +curl "${CURL_OPTS[@]}" -o ./res/fingerprint-server-api.yaml "$schemaUrl" + +echo "OpenAPI schema download complete." ./generate.sh