name: Web Release
on:
  push:
    branches: [main]
    paths:
      - 'lib/**'
      - 'web/**'
      - 'assets/**'
      - 'pubspec.yaml'
      - 'pubspec.lock'
      - 'l10n.yaml'
      - 'analysis_options.yaml'
      - '.github/workflows/deploy-web.yml'
  workflow_dispatch:

permissions:
  contents: read

concurrency:
  group: web-release-${{ github.ref }}
  cancel-in-progress: true

jobs:
  web:
    name: Flutter Web Artifact
    runs-on: ubuntu-24.04
    timeout-minutes: 20
    env:
    steps:
      - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
      - uses: ./.github/actions/android-app/flutter-setup
        with:
          channel: stable
          cache: true
      - name: Authenticate private git dependencies
        shell: bash
        env:
          GIT_PRIVATE_TOKEN: ${{ secrets.GIT_PRIVATE_TOKEN }}
        run: |
          if [ -z "${GIT_PRIVATE_TOKEN:-}" ]; then
            echo "No GIT_PRIVATE_TOKEN secret; private git dependencies must carry their own credentials."
            exit 0
          fi
          echo "::add-mask::$GIT_PRIVATE_TOKEN"
          git config --global \
            url."https://x-access-token:${GIT_PRIVATE_TOKEN}@github.com/".insteadOf "https://github.com/"
      - name: Build Flutter web release
        shell: bash
        run: |
          flutter pub get
          if [ -f l10n.yaml ]; then flutter gen-l10n; fi
          flutter build web --release --no-web-resources-cdn --build-number="${GITHUB_RUN_NUMBER}"
      - name: Retain Flutter web release
        uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5
        env:
          NODE_OPTIONS: --require "${{ github.workspace }}/.github/actions/android-app/scripts/artifact_env.cjs"
        with:
          name: web-${{ github.event.repository.name }}-${{ github.run_number }}
          path: build/web
          if-no-files-found: error
          retention-days: 30
