From 29d5d8b9ff66ca4c938da22a2762276b32021a66 Mon Sep 17 00:00:00 2001 From: Dmitry Nefedov <10544660+farag2@users.noreply.github.com> Date: Thu, 8 Oct 2026 23:18:05 +0300 Subject: [PATCH] Updated CI/CD scripts --- .github/workflows/Cursors.yml | 7 ++- .github/workflows/HEVC.yml | 6 +- Scripts/Cursors_API.ps1 | 58 ------------------ Scripts/{Cursors.ps1 => Cursors_Selenium.ps1} | 2 +- Scripts/Download_Cursors.ps1 | 56 +++++++++++++++++ Scripts/{HEVC.ps1 => Download_HEVC.ps1} | 1 - ..._adguard.ps1 => Download_HEVC_adguard.ps1} | 0 Scripts/Get_DeviantArt_Token_Locally.ps1 | 61 +++++++++++++++++++ 8 files changed, 127 insertions(+), 64 deletions(-) delete mode 100644 Scripts/Cursors_API.ps1 rename Scripts/{Cursors.ps1 => Cursors_Selenium.ps1} (96%) create mode 100644 Scripts/Download_Cursors.ps1 rename Scripts/{HEVC.ps1 => Download_HEVC.ps1} (99%) rename Scripts/{HEVC_adguard.ps1 => Download_HEVC_adguard.ps1} (100%) create mode 100644 Scripts/Get_DeviantArt_Token_Locally.ps1 diff --git a/.github/workflows/Cursors.yml b/.github/workflows/Cursors.yml index f4852749..1473b23d 100644 --- a/.github/workflows/Cursors.yml +++ b/.github/workflows/Cursors.yml @@ -15,8 +15,13 @@ jobs: uses: actions/checkout@main - name: Download cursors + env: + DEVIANTART_CLIENT_ID: ${{ secrets.DEVIANTART_CLIENT_ID }} + DEVIANTART_CLIENT_SECRET: ${{ secrets.DEVIANTART_CLIENT_SECRET }} + DEVIANTART_TOKEN: ${{ secrets.DEVIANTART_TOKEN }} + GH_TOKEN: ${{ secrets.CURSOR_PAT }} run: | - . "Scripts\Cursors.ps1" + . "Scripts\Download_Cursors.ps1" - name: Commit and push changes run: | diff --git a/.github/workflows/HEVC.yml b/.github/workflows/HEVC.yml index e1e90e84..00ce4619 100644 --- a/.github/workflows/HEVC.yml +++ b/.github/workflows/HEVC.yml @@ -16,7 +16,7 @@ jobs: - name: Download HEVC package run: | - . "Scripts\HEVC.ps1" + . "Scripts\Download_HEVC.ps1" - name: Commit and push changes run: | @@ -24,7 +24,7 @@ jobs: git config user.name "${{ github.actor }}" git config user.email "${{ github.actor }}@users.noreply.github.com" - git add HEVC/Microsoft.HEVCVideoExtension_8wekyb3d8bbwe.appx + git add HEVC/Microsoft.HEVCVideoExtension_8wekyb3d8bbwe.appxbundle git add HEVC/HEVC_version.txt - git commit -m "Update Microsoft.HEVCVideoExtension_8wekyb3d8bbwe.appx" + git commit -m "Update Microsoft.HEVCVideoExtension_8wekyb3d8bbwe.appxbundle" git push diff --git a/Scripts/Cursors_API.ps1 b/Scripts/Cursors_API.ps1 deleted file mode 100644 index 8b7c2ced..00000000 --- a/Scripts/Cursors_API.ps1 +++ /dev/null @@ -1,58 +0,0 @@ -# https://www.deviantart.com/team/status-update/An-adjustments-being-made-to-1307747979 - -# Start listiner to copy code from URL -$Listener = [System.Net.HttpListener]::new() -# With "/" -$Listener.Prefixes.Add('http://localhost:8080/cb/') -$Listener.Start() - -$Bytes = [byte[]]::new(32) -[System.Security.Cryptography.RandomNumberGenerator]::Create().GetBytes($Bytes) -$codeVerifier = [Convert]::ToBase64String($Bytes).TrimEnd('=').Replace('+','-').Replace('/','_') -$Hash = [System.Security.Cryptography.SHA256]::Create().ComputeHash([Text.Encoding]::ASCII.GetBytes($CodeVerifier)) -$CodeChallenge = [Convert]::ToBase64String($Hash).TrimEnd('=').Replace('+','-').Replace('/','_') -$state = [guid]::NewGuid().ToString('N') -$ClientId = $env:DEVIANTART_CLIENT_ID -$RedirectURL = [uri]::EscapeDataString("http://localhost:8080/cb") -Start-Process -FilePath "https://www.deviantart.com/oauth2/authorize?response_type=code&client_id=$clientId&redirect_uri=$RedirectURL&scope=browse&state=$State&code_challenge=$CodeChallenge&code_challenge_method=S256" - -# Blocks until the browser hits the redirect_uri -$context = $Listener.GetContext() -$request = $context.Request -$code = $request.QueryString['code'] -$context.Response.Close() -$Listener.Stop() - -# Get access token -# https://deviantart.readme.io/docs/authentication -$Body = @{ - grant_type = "authorization_code" - client_id = $env:DEVIANTART_CLIENT_ID - client_secret = $env:DEVIANTART_CLIENT_SECRET - redirect_uri = "http://localhost:8080/cb" - code = $code - code_verifier = $codeVerifier -} -$Parameters = @{ - Uri = "https://www.deviantart.com/oauth2/token" - Body = $Body - Method = "Post" - Verbose = $true - UseBasicParsing = $true -} -$Response = Invoke-RestMethod @Parameters - -# Get download URL -# UUID is 8A8DC033-242C-DD2E-EDB0-CC864772D5F4 -# https://www.deviantart.com/jepricreations/art/Windows-11-Cursors-Concept-886489356 -$Headers = @{ - Authorization = "Bearer $($Response.access_token)" -} -$Parameters = @{ - Uri = "https://www.deviantart.com/api/v1/oauth2/deviation/download/8A8DC033-242C-DD2E-EDB0-CC864772D5F4?mature_content=true" - Headers = $Headers - Verbose = $true - UseBasicParsing = $true -} -$Response = Invoke-RestMethod @Parameters -$Response.src diff --git a/Scripts/Cursors.ps1 b/Scripts/Cursors_Selenium.ps1 similarity index 96% rename from Scripts/Cursors.ps1 rename to Scripts/Cursors_Selenium.ps1 index 611f63ae..dc1edae8 100644 --- a/Scripts/Cursors.ps1 +++ b/Scripts/Cursors_Selenium.ps1 @@ -1,7 +1,7 @@ # https://www.deviantart.com/jepricreations/art/Windows-11-Cursors-Concept-886489356 # https://jepricreations.com/products/w11-cursor-concept-free -# We cannot download archive using Deviant Art's API due to limitations as it requires a human interection +# We cannot automate downlaoding archive using Deviant Art's API due to limitations as it requires a human interection # https://www.deviantart.com/team/status-update/An-adjustments-being-made-to-1307747979 Get-Process -Name msedgedriver, msedge -ErrorAction Ignore | Stop-Process -Force -ErrorAction Ignore diff --git a/Scripts/Download_Cursors.ps1 b/Scripts/Download_Cursors.ps1 new file mode 100644 index 00000000..f0f44190 --- /dev/null +++ b/Scripts/Download_Cursors.ps1 @@ -0,0 +1,56 @@ +# https://www.deviantart.com/team/status-update/An-adjustments-being-made-to-1307747979 + +# Get access token +# https://www.deviantart.com/developers/authentication +$Body = @{ + grant_type = "refresh_token" + client_id = $env:DEVIANTART_CLIENT_ID + client_secret = $env:DEVIANTART_CLIENT_SECRET + refresh_token = $env:DEVIANTART_TOKEN +} +$Parameters = @{ + Uri = "https://www.deviantart.com/oauth2/token" + Body = $Body + Method = "Post" + Verbose = $true + UseBasicParsing = $true +} +$Token = Invoke-RestMethod @Parameters + +# Hide tokens in the workflow log +Write-Output -InputObject "::add-mask::$($Token.access_token)" +Write-Output -InputObject "::add-mask::$($Token.refresh_token)" + +# A new refresh token is issued on every refresh and the previous one stops working, so save the new one for the next run before doing anything else +# GITHUB_TOKEN cannot write secrets, so GH_TOKEN has to be a personal access token with the "Secrets: Read and write" permission +gh secret set DEVIANTART_TOKEN --body $Token.refresh_token --repo $env:GITHUB_REPOSITORY + +# Get download URL +# UUID is 8A8DC033-242C-DD2E-EDB0-CC864772D5F4 +# https://www.deviantart.com/jepricreations/art/Windows-11-Cursors-Concept-886489356 +$Headers = @{ + Authorization = "Bearer $($Token.access_token)" +} +$Parameters = @{ + Uri = "https://www.deviantart.com/api/v1/oauth2/deviation/download/8A8DC033-242C-DD2E-EDB0-CC864772D5F4?mature_content=true" + Headers = $Headers + Verbose = $true + UseBasicParsing = $true +} +$Response = Invoke-RestMethod @Parameters + +# Download the archive to a temp folder first to not overwrite the valid one in the repo with a broken download +$Parameters = @{ + Uri = $Response.src + OutFile = "$env:RUNNER_TEMP\w11-cursor-concept-free.zip" + UseBasicParsing = $true + Verbose = $true +} +Invoke-WebRequest @Parameters + +$Parameters = @{ + Path = "$env:RUNNER_TEMP\w11-cursor-concept-free.zip" + Destination = "Cursors\w11-cursor-concept-free.zip" + Force = $true +} +Move-Item @Parameters diff --git a/Scripts/HEVC.ps1 b/Scripts/Download_HEVC.ps1 similarity index 99% rename from Scripts/HEVC.ps1 rename to Scripts/Download_HEVC.ps1 index facf9b44..06aec5e2 100644 --- a/Scripts/HEVC.ps1 +++ b/Scripts/Download_HEVC.ps1 @@ -171,7 +171,6 @@ $Parameters.Uri = "$Uri/secured" $Parameters.Body = $FileRequest $TempURL = ((Invoke-RestMethod @Parameters).Envelope.Body.GetExtendedUpdateInfo2Response.GetExtendedUpdateInfo2Result.FileLocations.FileLocation | Where-Object -FilterScript {$_.Url.Contains("tlu")}).Url -# Download archive if (-not (Test-Path -Path HEVC)) { New-Item -Path HEVC -ItemType Directory -Force diff --git a/Scripts/HEVC_adguard.ps1 b/Scripts/Download_HEVC_adguard.ps1 similarity index 100% rename from Scripts/HEVC_adguard.ps1 rename to Scripts/Download_HEVC_adguard.ps1 diff --git a/Scripts/Get_DeviantArt_Token_Locally.ps1 b/Scripts/Get_DeviantArt_Token_Locally.ps1 new file mode 100644 index 00000000..ce9de267 --- /dev/null +++ b/Scripts/Get_DeviantArt_Token_Locally.ps1 @@ -0,0 +1,61 @@ +# Run once locally to sign in to DeviantArt in a browser and get a refresh token for CI/CD +# https://www.deviantart.com/studio/apps + +$client_id = "" +$client_secret = "" + +$Bytes = [byte[]]::new(32) +[System.Security.Cryptography.RandomNumberGenerator]::Create().GetBytes($Bytes) +$CodeVerifier = [Convert]::ToBase64String($Bytes).TrimEnd("=").Replace("+", "-").Replace("/", "_") +$Hash = [System.Security.Cryptography.SHA256]::Create().ComputeHash([Text.Encoding]::ASCII.GetBytes($CodeVerifier)) +$CodeChallenge = [Convert]::ToBase64String($Hash).TrimEnd("=").Replace("+", "-").Replace("/", "_") +$State = [guid]::NewGuid().ToString("N") +$RedirectURL = [uri]::EscapeDataString("http://localhost:8080/cb") + +# Start listener to get code from redirect URL +$Listener = [System.Net.HttpListener]::new() +# With "/" +$Listener.Prefixes.Add("http://localhost:8080/cb/") + +try +{ + $Listener.Start() + + Start-Process -FilePath "https://www.deviantart.com/oauth2/authorize?response_type=code&client_id=$client_id&redirect_uri=$RedirectURL&scope=browse&state=$State&code_challenge=$CodeChallenge&code_challenge_method=S256" + + # Blocks until the browser hits the redirect_uri + $Context = $Listener.GetContext() + $Code = $Context.Request.QueryString["code"] + $ReturnedState = $Context.Request.QueryString["state"] + + $Buffer = [Text.Encoding]::UTF8.GetBytes("Done. You can close this tab.") + $Context.Response.OutputStream.Write($Buffer, 0, $Buffer.Length) + $Context.Response.Close() +} +finally +{ + # Release http://localhost:8080/cb/ even if the script failed or was interrupted + $Listener.Close() +} + +$Body = @{ + grant_type = "authorization_code" + client_id = $client_id + client_secret = $client_secret + redirect_uri = "http://localhost:8080/cb" + code = $Code + code_verifier = $CodeVerifier +} +$Parameters = @{ + Uri = "https://www.deviantart.com/oauth2/token" + Body = $Body + Method = "Post" + Verbose = $true + UseBasicParsing = $true +} +$Token = Invoke-RestMethod @Parameters + +$Token.refresh_token + +Set-Clipboard -Value $Token.refresh_token +Start-Process -FilePath "https://github.com/farag2/Sophia-Script-for-Windows/settings/secrets/actions/DEVIANTART_TOKEN"