Skip to content

fix: remove hardcoded bearer#1467

Merged
HarithaVattikuti merged 1 commit intoactions:mainfrom
marco-ippolito:fix-bearer-token
Feb 19, 2026
Merged

fix: remove hardcoded bearer#1467
HarithaVattikuti merged 1 commit intoactions:mainfrom
marco-ippolito:fix-bearer-token

Conversation

@marco-ippolito
Copy link
Contributor

@marco-ippolito marco-ippolito commented Jan 14, 2026

Followup of #1240

Description:
This change makes the mirror usable.
Right now Immagine we setup the value of mirror-token to foo.
In this line the value is used as

headers['Authorization'] = `Bearer ${this.nodeInfo.mirrorToken}`;

Bearer foo but in other places such as:

this.nodeInfo.mirrorToken

this.nodeInfo.mirrorToken

its used as is.

But if we change the value to Bearer foo,

headers['Authorization'] = `Bearer ${this.nodeInfo.mirrorToken}`;

here it becomes Bearer Bearer foo which is incorrect, but works everywhere else.

So this PR makes it that if its a Bearer, the user needs to be explicit.

Related issue:
Add link to the related issue.

Check list:

  • Mark if documentation changes are required.
  • Mark if tests were added or updated to cover the changes.

@marco-ippolito marco-ippolito requested a review from a team as a code owner January 14, 2026 16:01
Copilot AI review requested due to automatic review settings January 14, 2026 16:01
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes an inconsistency in how the mirror-token is used across the codebase. Previously, the token was hardcoded with a "Bearer" prefix in one location (getNodeJsVersions method) but used as-is in all other locations (downloadTool calls). This inconsistency made the mirror feature unusable because users had to choose between making one call work or the others. The fix removes the hardcoded "Bearer" prefix, requiring users to explicitly include the authentication scheme in their token if needed.

Changes:

  • Removed hardcoded "Bearer" prefix from Authorization header in getNodeJsVersions method
  • Updated compiled distribution file to reflect source changes

Reviewed changes

Copilot reviewed 2 out of 3 changed files in this pull request and generated no comments.

File Description
src/distributions/base-distribution.ts Removes "Bearer" prefix from Authorization header to make token usage consistent
dist/setup/index.js Compiled distribution reflecting the source change

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@marco-ippolito
Copy link
Contributor Author

marco-ippolito commented Jan 21, 2026

Hi @aparnajyothi-y, @priyagupta108 can you please take a look

@marco-ippolito
Copy link
Contributor Author

friendly ping

@HarithaVattikuti HarithaVattikuti merged commit efcb663 into actions:main Feb 19, 2026
228 checks passed
mergify bot added a commit to ArcadeData/arcadedb-usecases that referenced this pull request Mar 6, 2026
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4.4.0 to 6.3.0.
Release notes

*Sourced from [actions/setup-node's releases](https://github.com/actions/setup-node/releases).*

> v6.3.0
> ------
>
> What's Changed
> --------------
>
> ### Enhancements:
>
> * Support parsing `devEngines` field by [`@​susnux`](https://github.com/susnux) in [actions/setup-node#1283](https://redirect.github.com/actions/setup-node/pull/1283)
>
> > When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node.
>
> ### Dependency updates:
>
> * Fix npm audit issues by [`@​gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1491](https://redirect.github.com/actions/setup-node/pull/1491)
> * Replace uuid with crypto.randomUUID() by [`@​trivikr`](https://github.com/trivikr) in [actions/setup-node#1378](https://redirect.github.com/actions/setup-node/pull/1378)
> * Upgrade minimatch from 3.1.2 to 3.1.5 by [`@​dependabot`](https://github.com/dependabot) in [actions/setup-node#1498](https://redirect.github.com/actions/setup-node/pull/1498)
>
> ### Bug fixes:
>
> * Remove hardcoded bearer for mirror-url [`@​marco-ippolito`](https://github.com/marco-ippolito) in [actions/setup-node#1467](https://redirect.github.com/actions/setup-node/pull/1467)
> * Scope test lockfiles by package manager and update cache tests by [`@​gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1495](https://redirect.github.com/actions/setup-node/pull/1495)
>
> New Contributors
> ----------------
>
> * [`@​susnux`](https://github.com/susnux) made their first contribution in [actions/setup-node#1283](https://redirect.github.com/actions/setup-node/pull/1283)
>
> **Full Changelog**: <actions/setup-node@v6...v6.3.0>
>
> v6.2.0
> ------
>
> What's Changed
> --------------
>
> ### Documentation
>
> * Documentation update related to absence of Lockfile by [`@​mahabaleshwars`](https://github.com/mahabaleshwars) in [actions/setup-node#1454](https://redirect.github.com/actions/setup-node/pull/1454)
> * Correct mirror option typos by [`@​MikeMcC399`](https://github.com/MikeMcC399) in [actions/setup-node#1442](https://redirect.github.com/actions/setup-node/pull/1442)
> * Readme update on checkout version v6 by [`@​deining`](https://github.com/deining) in [actions/setup-node#1446](https://redirect.github.com/actions/setup-node/pull/1446)
> * Readme typo fixes [`@​munyari`](https://github.com/munyari) in [actions/setup-node#1226](https://redirect.github.com/actions/setup-node/pull/1226)
> * Advanced document update on checkout version v6 by [`@​aparnajyothi-y`](https://github.com/aparnajyothi-y) in [actions/setup-node#1468](https://redirect.github.com/actions/setup-node/pull/1468)
>
> ### Dependency updates:
>
> * Upgrade `@​actions/cache` to v5.0.1 by [`@​salmanmkc`](https://github.com/salmanmkc) in [actions/setup-node#1449](https://redirect.github.com/actions/setup-node/pull/1449)
>
> New Contributors
> ----------------
>
> * [`@​mahabaleshwars`](https://github.com/mahabaleshwars) made their first contribution in [actions/setup-node#1454](https://redirect.github.com/actions/setup-node/pull/1454)
> * [`@​MikeMcC399`](https://github.com/MikeMcC399) made their first contribution in [actions/setup-node#1442](https://redirect.github.com/actions/setup-node/pull/1442)
> * [`@​deining`](https://github.com/deining) made their first contribution in [actions/setup-node#1446](https://redirect.github.com/actions/setup-node/pull/1446)
> * [`@​munyari`](https://github.com/munyari) made their first contribution in [actions/setup-node#1226](https://redirect.github.com/actions/setup-node/pull/1226)
>
> **Full Changelog**: <actions/setup-node@v6...v6.2.0>
>
> v6.1.0
> ------
>
> What's Changed
> --------------
>
> ### Enhancement:
>
> * Remove always-auth configuration handling by [`@​priyagupta108`](https://github.com/priyagupta108) in [actions/setup-node#1436](https://redirect.github.com/actions/setup-node/pull/1436)
>
> ### Dependency updates:
>
> * Upgrade `@​actions/cache` from 4.0.3 to 4.1.0 by [`@​dependabot`](https://github.com/dependabot)[bot] in [actions/setup-node#1384](https://redirect.github.com/actions/setup-node/pull/1384)
> * Upgrade actions/checkout from 5 to 6 by [`@​dependabot`](https://github.com/dependabot)[bot] in [actions/setup-node#1439](https://redirect.github.com/actions/setup-node/pull/1439)

... (truncated)


Commits

* [`53b8394`](actions/setup-node@53b8394) Bump minimatch from 3.1.2 to 3.1.5 ([#1498](https://redirect.github.com/actions/setup-node/issues/1498))
* [`54045ab`](actions/setup-node@54045ab) Scope test lockfiles by package manager and update cache tests ([#1495](https://redirect.github.com/actions/setup-node/issues/1495))
* [`c882bff`](actions/setup-node@c882bff) Replace uuid with crypto.randomUUID() ([#1378](https://redirect.github.com/actions/setup-node/issues/1378))
* [`774c1d6`](actions/setup-node@774c1d6) feat(node-version-file): support parsing `devEngines` field ([#1283](https://redirect.github.com/actions/setup-node/issues/1283))
* [`efcb663`](actions/setup-node@efcb663) fix: remove hardcoded bearer ([#1467](https://redirect.github.com/actions/setup-node/issues/1467))
* [`d02c89d`](actions/setup-node@d02c89d) Fix npm audit issues ([#1491](https://redirect.github.com/actions/setup-node/issues/1491))
* [`6044e13`](actions/setup-node@6044e13) Docs: bump actions/checkout from v5 to v6 ([#1468](https://redirect.github.com/actions/setup-node/issues/1468))
* [`8e49463`](actions/setup-node@8e49463) Fix README typo ([#1226](https://redirect.github.com/actions/setup-node/issues/1226))
* [`621ac41`](actions/setup-node@621ac41) README.md: bump to latest released checkout version v6 ([#1446](https://redirect.github.com/actions/setup-node/issues/1446))
* [`2951748`](actions/setup-node@2951748) Bump `@​actions/cache` to v5.0.1 ([#1449](https://redirect.github.com/actions/setup-node/issues/1449))
* Additional commits viewable in [compare view](actions/setup-node@49933ea...53b8394)
  
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility\_score?dependency-name=actions/setup-node&package-manager=github\_actions&previous-version=4.4.0&new-version=6.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants