auth/dist
Brian Lalor 12060449e8
Add selective retries for STS token exchange (#532)
## Summary

The workload identity flow retries GitHub OIDC token retrieval, but
`@actions/http-client` does not retry the POST to Google Security Token
Service. A transient connection reset or socket timeout therefore ends
authentication on the first failed exchange.

This change adds four bounded STS attempts with 100, 200, and 400 ms
backoffs. Retries are limited to connection failures and HTTP 408, 429,
500, 502, 503, and 504 responses. HTTP 400, 401, 403, empty responses,
and unknown errors fail without retrying.

Attempt diagnostics contain only the operation, STS hostname, status or
classified error, and attempt count. The existing STS request and
computed-audience debug messages were removed so these diagnostics do
not include the OIDC assertion, returned access token, headers,
credential data, service account, or workload identity provider
resource.

Mocked tests cover each retryable HTTP status, connection errors, the
uncoded `@actions/http-client` socket timeout, permanent HTTP failures,
the four-attempt limit, and diagnostic redaction.
2026-07-29 16:22:35 -04:00
..
main Add selective retries for STS token exchange (#532) 2026-07-29 16:22:35 -04:00
post Release: v3.0.0 (#510) 2025-08-28 18:51:40 +00:00