bypass Vercel deployment protection on preview API calls

action API calls to preview deployments were getting 401'd by Vercel's
deployment protection. add x-vercel-protection-bypass header to the 3
server-to-server fetch sites when VERCEL_AUTOMATION_BYPASS_SECRET is set.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Colin McDonnell
2026-02-13 15:25:32 +00:00
committed by pullfrog[bot]
parent d7759734f2
commit dc611c9f78
7 changed files with 1633 additions and 1597 deletions
+10 -2
View File
@@ -25682,7 +25682,14 @@ import { createSign } from "node:crypto";
// utils/apiUrl.ts
function getApiUrl() {
return process.env.API_URL || "https://pullfrog.com";
const url = process.env.API_URL || "https://pullfrog.com";
log.debug(`resolved API_URL: ${url}`);
return url;
}
function getVercelBypassHeaders() {
const secret = process.env.VERCEL_AUTOMATION_BYPASS_SECRET;
if (!secret) return {};
return { "x-vercel-protection-bypass": secret };
}
// utils/retry.ts
@@ -25741,7 +25748,8 @@ async function acquireTokenViaOIDC(opts) {
method: "POST",
headers: {
Authorization: `Bearer ${oidcToken}`,
"Content-Type": "application/json"
"Content-Type": "application/json",
...getVercelBypassHeaders()
},
signal: controller.signal
};