// CI/CD for Gogs: push and pull requests targeting main.
// Tests/package run in Docker (DinD). Release publishes the HPI to Gogs.

pipeline {
  agent none

  options {
    timestamps()
    disableConcurrentBuilds()
    timeout(time: 45, unit: 'MINUTES')
    buildDiscarder(logRotator(numToKeepStr: '20', artifactNumToKeepStr: '10'))
  }

  stages {
    stage('Build') {
      agent {
        docker {
          image 'ura-ci-maven:21'
          label 'built-in'
          alwaysPull false
          args '-u root -v jenkins-m2-cache:/root/.m2 -e MAVEN_OPTS=-Xmx1024m'
        }
      }
      stages {
        stage('Checkout') {
          steps {
            script {
              def sha = env.pr_head_sha ?: env.after ?: 'main'
              if (!sha?.trim() || sha == 'null' || sha == '0000000000000000000000000000000000000000') {
                sha = 'main'
              }
              echo "Gogs event ref=${env.ref} action=${env.action} pr=#${env.pr_number} sha=${sha}"
              env.RELEASE_SHA = sha
              checkout([
                $class: 'GitSCM',
                branches: [[name: sha]],
                extensions: [[$class: 'CloneOption', shallow: false, noTags: false]],
                userRemoteConfigs: [[url: 'https://git.barcelos.dev/allan/jenkins-mfa-auth-plugin.git']]
              ])
            }
          }
        }
        stage('Test') {
          steps {
            sh 'mvn -B -ntp verify'
          }
          post {
            always {
              junit allowEmptyResults: true, testResults: 'target/surefire-reports/*.xml'
            }
          }
        }
        stage('Package') {
          steps {
            sh 'mvn -B -ntp -DskipTests -Dset.changelist package'
            sh 'ls -la target/*.hpi'
            archiveArtifacts artifacts: 'target/*.hpi', fingerprint: true
            stash name: 'hpi', includes: 'target/*.hpi'
          }
        }
      }
      post {
        always {
          sh 'chmod -R a+rwX "$WORKSPACE" || true'
        }
      }
    }

    stage('Release') {
      when {
        allOf {
          expression { env.ref == 'refs/heads/main' }
          expression { !env.pr_number?.trim() || env.pr_number == 'null' }
        }
      }
      agent { label 'built-in' }
      steps {
        unstash 'hpi'
        withCredentials([string(credentialsId: 'gogs-release-token', variable: 'GOGS_RELEASE_TOKEN')]) {
          sh '''
            set -euo pipefail
            HPI=$(ls -1 target/*.hpi | head -1)
            SHA="${RELEASE_SHA:-${after:-}}"
            if [ -z "$SHA" ] || [ "$SHA" = "null" ]; then
              SHA=$(git rev-parse HEAD 2>/dev/null || echo "")
            fi
            TAG="1.0.${BUILD_NUMBER}"
            echo "Publishing ${HPI} as Gogs release ${TAG} sha=${SHA}"
            curl -fsS -X POST \
              -H "X-Release-Token: ${GOGS_RELEASE_TOKEN}" \
              -F "file=@${HPI}" \
              -F "tag=${TAG}" \
              -F "sha=${SHA}" \
              -F "title=mfa-totp ${TAG}" \
              -F "body=Jenkins build #${BUILD_NUMBER} (${SHA}). Artifact: $(basename "$HPI")" \
              http://host.docker.internal:9377/publish
          '''
        }
      }
    }
  }
}
