From ad2c73d11e45e220a69a8e0067306643e6d911ec Mon Sep 17 00:00:00 2001 From: engineer Date: Tue, 18 Aug 2026 23:12:46 -0700 Subject: [PATCH] debug(ci): add org-detail and Node-fetch probes to narrow the 403 down Isolates whether the 403 is curl/UA-specific (vs the plain fetch() the failing script actually uses) and whether it's specific to the listing endpoint vs a non-listing org-detail GET. Co-Authored-By: Paperclip --- .github/workflows/debug-sentry-egress.yml | 32 +++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/.github/workflows/debug-sentry-egress.yml b/.github/workflows/debug-sentry-egress.yml index 110e46f..da1ecd9 100644 --- a/.github/workflows/debug-sentry-egress.yml +++ b/.github/workflows/debug-sentry-egress.yml @@ -65,4 +65,36 @@ jobs: echo '```' cat /tmp/auth.json echo '```' + echo '' + echo '### Same endpoint, org detail (not a listing) — /organizations/{org}/' + echo '```' + curl -s -H "Authorization: Bearer ${SENTRY_AUTH_TOKEN}" \ + "https://sentry.io/api/0/organizations/${SENTRY_ORG}/" \ + -o /tmp/orgdetail.json -w "http_code=%{http_code}\n" + echo '```' + } | tee -a "$GITHUB_STEP_SUMMARY" + + - uses: actions/setup-node@v6 + with: + node-version: 24 + + - name: Node fetch probe (matches scripts/sentry-volume-report.mjs exactly, no explicit User-Agent) + env: + SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_PRODUCT_INTELLIGENCE_TOKEN || secrets.SENTRY_AUTH_TOKEN }} + SENTRY_ORG: ${{ secrets.SENTRY_ORG || 'vibetechnologies' }} + run: | + { + echo '' + echo '### Node fetch probe (same client the failing script uses)' + echo '```' + node --input-type=module -e ' + const token = process.env.SENTRY_AUTH_TOKEN + const org = process.env.SENTRY_ORG + for (const path of ["/organizations/" + org + "/projects/", "/auth/"]) { + const res = await fetch("https://sentry.io/api/0" + path, { headers: { Authorization: "Bearer " + token } }) + const body = await res.text() + console.log(path, "->", res.status, body.slice(0, 200)) + } + ' 2>&1 || true + echo '```' } | tee -a "$GITHUB_STEP_SUMMARY"