GitHub Action部署Firebase Hosting预览通道失败求助
解决Firebase Hosting预览通道GitHub Action 403权限问题
问题背景
搭建基于Vite的Svelte项目,计划部署到Firebase。主分支部署的GitHub Action可正常运行,但Pull Request触发的预览通道部署Action持续报403错误,尝试切换pull_request和pull_request_target触发条件均无效。
原Action代码
name: Deploy to Preview Channel on: pull_request_target: jobs: build_and_preview: runs-on: ubuntu-latest steps: - uses: actions/checkout@v2 - run: npm install - run: npm run build - uses: FirebaseExtended/action-hosting-deploy@v0 with: repoToken: "${{ secrets.GITHUB_TOKEN }}" firebaseServiceAccount: "${{ secrets.FIREBASE_SERVICE_ACCOUNT_SVELTE_WETHER_SITE }}" expires: 10d projectId: your-Firebase-project-ID
报错信息
Run FirebaseExtended/action-hosting-deploy@v0 /home/runner/work/_actions/FirebaseExtended/action-hosting-deploy/v0/bin/action.min.js:3759 const error = new RequestError(message, status, { ^ RequestError [HttpError]: Resource not accessible by integration at /home/runner/work/_actions/FirebaseExtended/action-hosting-deploy/v0/bin/action.min.js:3759:31 at processTicksAndRejections (node:internal/process/task_queues:96:5) at async createCheck (/home/runner/work/_actions/FirebaseExtended/action-hosting-deploy/v0/bin/action.min.js:5680:17) at async run (/home/runner/work/_actions/FirebaseExtended/action-hosting-deploy/v0/bin/action.min.js:11435:14) { status: 403,
解决方案
这个403错误核心是权限不足,结合GitHub Action的权限机制和Firebase部署Action的特性,可通过以下步骤修复:
升级Action版本
action-hosting-deploy@v0是旧版本,存在权限处理的兼容性问题,直接升级到最新稳定版(如v1)。明确Workflow权限
GitHub Action默认权限有限,需显式授予GITHUB_TOKEN必要权限,让Action能创建检查、更新PR评论。正确拉取PR分支代码
若使用pull_request_target,默认拉取的是base分支代码,需配置actions/checkout切换到PR分支;推荐直接用pull_request触发,配合指定分支拉取。显式指定预览通道ID
为每个PR生成独立的预览通道,方便管理和识别。
修改后的Action代码
name: Deploy to Preview Channel on: pull_request: types: [opened, synchronize, reopened] permissions: checks: write pull-requests: write contents: read jobs: build_and_preview: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 with: ref: ${{ github.event.pull_request.head.sha }} persist-credentials: false - run: npm install - run: npm run build - uses: FirebaseExtended/action-hosting-deploy@v1 with: repoToken: "${{ secrets.GITHUB_TOKEN }}" firebaseServiceAccount: "${{ secrets.FIREBASE_SERVICE_ACCOUNT_SVELTE_WETHER_SITE }}" expires: 10d projectId: your-Firebase-project-ID channelId: pr-${{ github.event.number }}
关键修改说明
- 触发条件改用
pull_request,并指定触发类型,确保PR更新时自动重新部署预览 - 添加
permissions字段,授予检查写入、PR写入权限,解决403权限问题 actions/checkout指定拉取PR分支的SHA,同时禁用凭证持久化避免权限冲突- 升级
action-hosting-deploy到v1,修复旧版本的权限逻辑缺陷 - 用
channelId: pr-${{ github.event.number }}生成与PR编号绑定的预览通道,便于追踪对应关系
内容的提问来源于stack exchange,提问作者kenni
相关产品推荐
相关产品推荐

