name: Manual Publish Package
on:
  workflow_dispatch:
    inputs:
      prerelease:
        description: 'Is this a prerelease. If so, then the latest tag will not be updated in npm.'
        type: boolean
        required: true
      dry_run:
        description: 'Is this a dry run. If so no package will be published.'
        type: boolean
        required: true

jobs:
  build-publish:
    runs-on: ubuntu-latest
    # Needed to get tokens during publishing.
    permissions:
      id-token: write
      contents: read
    steps:
      - uses: actions/checkout@v4

      - uses: actions/setup-node@v4
        with:
          node-version: 20.x
          registry-url: 'https://registry.npmjs.org'

      - uses: launchdarkly/gh-actions/actions/release-secrets@release-secrets-v1.0.0
        name: 'Get the NPM token'
        with:
          aws_assume_role: ${{ vars.AWS_ROLE_ARN }}
          ssm_parameter_pairs: '/production/common/releasing/npm/token = NODE_AUTH_TOKEN'

      - uses: ./.github/actions/publish
        name: Publish Package to npm
        with:
          prerelease: ${{ inputs.prerelease }}
          dry_run: ${{ inputs.dry_run }}
