You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Codemagic配置Token后仍无法访问GitHub仓库,报403权限错误

解决Codemagic配置Token后仍出现GitHub权限403错误

可能的原因及解决方案

1. Token权限不足

GitHub Personal Access Token(PAT)需要具备对应仓库的推送权限:

  • 私有仓库:必须勾选repo权限
  • 公开仓库:至少勾选public_repo权限
  • 同时确认Token未过期、未被撤销

操作:登录GitHub进入「Settings → Developer settings → Personal access tokens」,检查现有Token权限,若不足则重新生成符合要求的Token,替换Codemagic环境变量中的对应值。

2. 环境变量引用不匹配

你的codemagic.yaml中使用$APP_PASSWORD调用Token,但需确认:

  • Codemagic的repo_credentials环境变量组中,Token的变量名确实是APP_PASSWORD
  • 变量未被禁用、已正确关联到当前项目

操作:在Codemagic项目的「Environment variables」页面,核对变量名与yaml中的引用完全一致,不一致则修改yaml中的变量名或调整环境变量名。

3. Git Credentials配置失效

当前脚本通过~/.git-credentials存储凭证的方式可能存在生效问题,更可靠的方式是直接修改Git远程仓库URL,将Token嵌入其中。

修改Configure Git脚本:

git config --global user.name "$GIT_USER_NAME"
git config --global user.email "$GIT_USER_EMAIL"
# 直接将Token嵌入远程仓库URL,确保推送时携带凭证
git remote set-url origin https://$APP_PASSWORD@github.com/Icarus-conf/fc_lang.git

4. 仓库分支权限限制

检查GitHub仓库的分支保护规则:

  • 进入仓库「Settings → Branches」
  • 确认web-branch和gh-pages分支未设置禁止推送的规则,且你的账号(或Token对应的账号)拥有推送权限

操作:临时关闭分支保护规则进行测试,若测试通过则调整规则允许指定账号推送。

5. Codemagic环境变量组未正确关联

确认repo_credentials环境变量组已被添加到当前Codemagic项目中,且处于启用状态。

操作:在Codemagic项目设置的「Environment variables」页面,检查Groups列表中是否包含repo_credentials,且开关处于开启状态。

修改后的完整codemagic.yaml示例

workflows:
  build_and_deploy:
    name: Build and Deploy to GitHub Pages
    environment:
      flutter: stable
      groups:
        - repo_credentials
    scripts:
      - name: Install dependencies
        script: |
          flutter pub get

      - name: Build web
        script: |
          flutter build web --release --no-tree-shake-icons

      - name: Verify build output
        script: |
          if [ ! -d "build/web" ]; then
            echo "Build directory does not exist. Aborting."
            exit 1
          fi
          ls -la build/web

      - name: Configure Git and update remote URL
        script: |
          git config --global user.name "$GIT_USER_NAME"
          git config --global user.email "$GIT_USER_EMAIL"
          # 直接设置带Token的远程仓库地址
          git remote set-url origin https://$APP_PASSWORD@github.com/Icarus-conf/fc_lang.git

      - name: Checkout web branch
        script: |
          git fetch --all
          if git show-ref --verify --quiet refs/heads/web-branch; then
            git checkout web-branch
          else
            git checkout -b web-branch
          fi

      - name: Copy built files to web branch
        script: |
          rm -rf *  # 保留.git目录,清除其他文件
          cp -R build/web/* .
          git add .
          git commit -m "Update web branch with latest changes from main" || echo "No changes to commit"
          git push origin web-branch

      - name: Deploy to GitHub Pages
        script: |
          git checkout -B gh-pages
          git add .
          git commit -m "Deploy to GitHub Pages" || echo "No changes to commit"
          git push --force origin gh-pages

artifacts:
  - build/web

内容的提问来源于stack exchange,提问作者Icarus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 09:38:12