diff --git a/app/config.sh b/app/config.sh index 650416d1d9..3deb636f37 100644 --- a/app/config.sh +++ b/app/config.sh @@ -28,6 +28,9 @@ NOTARIZATION_BUNDLE_ID="" NOTARIZATION_USER="" NOTARIZATION_TEAM_ID="" NOTARIZATION_PASSWORD="" +# Name of a notarytool keychain profile (see `xcrun notarytool store-credentials`), e.g., for an +# App Store Connect API key -- used instead of the Apple ID settings above if set +NOTARIZATION_PROFILE="" # Paths for Windows installer build NSIS_DIR='C:\Program Files (x86)\NSIS\' diff --git a/app/scripts/notarization_info b/app/scripts/notarization_info index 08b3b09794..51e6414bbe 100755 --- a/app/scripts/notarization_info +++ b/app/scripts/notarization_info @@ -4,6 +4,7 @@ set -euo pipefail SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )" ROOT_DIR="$(dirname "$SCRIPT_DIR")" . "$ROOT_DIR/config.sh" +. "$SCRIPT_DIR/utils.sh" function usage { echo "Usage: $0 id" @@ -15,5 +16,7 @@ if [[ -z "$id" ]]; then usage fi -xcrun notarytool log "$id" --apple-id "$NOTARIZATION_USER" --team-id "$NOTARIZATION_TEAM_ID" --password "$NOTARIZATION_PASSWORD" notary_log.json +prepare_notary_auth + +xcrun notarytool log "$id" "${notary_auth[@]}" notary_log.json cat notary_log.json diff --git a/app/scripts/notarize_mac_app b/app/scripts/notarize_mac_app index 89375ecdf9..5d27b309f6 100755 --- a/app/scripts/notarize_mac_app +++ b/app/scripts/notarize_mac_app @@ -4,6 +4,7 @@ set -euo pipefail SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )" ROOT_DIR="$(dirname "$SCRIPT_DIR")" . "$ROOT_DIR/config.sh" +. "$SCRIPT_DIR/utils.sh" function usage { echo "Usage: $0 file" @@ -15,5 +16,7 @@ if [[ -z "$file" ]]; then usage fi +prepare_notary_auth + echo "Uploading ${file##*/} to Apple for notarization" >&2 -xcrun notarytool submit $file --apple-id "$NOTARIZATION_USER" --team-id "$NOTARIZATION_TEAM_ID" --password="$NOTARIZATION_PASSWORD" --wait +xcrun notarytool submit $file "${notary_auth[@]}" --wait diff --git a/app/scripts/utils.sh b/app/scripts/utils.sh index 021cb2ddf5..2ed4314d40 100644 --- a/app/scripts/utils.sh +++ b/app/scripts/utils.sh @@ -167,3 +167,21 @@ function remove_between { exit 1 fi } + +# Set $notary_auth to notarytool authentication arguments: the keychain profile in +# NOTARIZATION_PROFILE if set, or else the Apple ID and app-specific password +function prepare_notary_auth { + if [[ -n "${NOTARIZATION_PROFILE:-}" ]]; then + notary_auth=(--keychain-profile "$NOTARIZATION_PROFILE") + if [[ -n "$KEYCHAIN" ]]; then + keychain_path="$HOME/Library/Keychains/$KEYCHAIN.keychain-db" + # The keychain may have auto-locked since signing + if [[ -n "$KEYCHAIN_PASSWORD" ]]; then + security unlock-keychain -p "$KEYCHAIN_PASSWORD" "$keychain_path" + fi + notary_auth+=(--keychain "$keychain_path") + fi + else + notary_auth=(--apple-id "$NOTARIZATION_USER" --team-id "$NOTARIZATION_TEAM_ID" --password "$NOTARIZATION_PASSWORD") + fi +}