#!/usr/bin/env bash
set -euo pipefail
: "${EVIDENCE_URL:?Full HTTPS upload destination}"
: "${EVIDENCE_TOKEN:?Upload-only bearer token}"
[[ "$EVIDENCE_URL" == https://* ]] || exit 2
[[ "$EVIDENCE_TOKEN" != *$'\n'* && "$EVIDENCE_TOKEN" != *$'\r'* ]] || exit 2
umask 077
headers="$(mktemp /tmp/devsecops-upload.XXXXXXXX)"
trap 'rm -f -- "$headers"' EXIT
printf 'Authorization: Bearer %s\n' "$EVIDENCE_TOKEN" > "$headers"
code="$(curl --fail --silent --show-error --proto '=https' --connect-timeout 30 \
  --max-time 600 --header "@$headers" --output /dev/null --write-out '%{http_code}' \
  --upload-file "${1:?archive file}" "$EVIDENCE_URL")"
[[ "$code" == 2?? ]] || { echo "Upload did not succeed: HTTP $code" >&2; exit 1; }
