fix(mosaic): honor seat-owned Gitea slots (#1529)
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/publish Pipeline was successful
Co-authored-by: Mosaic fleet seat code-be-02 <[email protected]>
This commit was merged in pull request #1529.
This commit is contained in:
@@ -44,8 +44,8 @@ account/token configured through `tools/_lib/credentials.sh`. That means every a
|
||||
fleet commits, pushes, and opens PRs under one identity — with no cryptographic
|
||||
separation between an author and a reviewer.
|
||||
|
||||
Both `git-credential-mosaic` and `get_gitea_token()` resolve an optional **per-agent
|
||||
identity**:
|
||||
`git-credential-mosaic`, `get_gitea_token()`, and the `gitea-mosaicstack` /
|
||||
`gitea-usc` arms of `load_credentials` resolve an optional **per-agent identity**:
|
||||
|
||||
1. `MOSAIC_GIT_IDENTITY` environment variable, or
|
||||
2. `git config --get mosaic.gitIdentity` (set per-worktree; persists on disk across
|
||||
@@ -65,6 +65,12 @@ The store is chosen by what the identity **is**, not by which file happens to ex
|
||||
`<brain>` is `MOSAIC_BRAIN_HOME` if set, else `~/.mosaic` — the same resolution
|
||||
`packages/mosaic/src/fleet/brain-home.ts` performs.
|
||||
|
||||
The Gitea arms of `load_credentials` obtain a seat token through the production
|
||||
`git-credential-mosaic` entrypoint, rather than reading the slot directly. That retains
|
||||
the entrypoint's clean-environment and process-ancestry fence. The Gitea URL remains
|
||||
provider configuration from the service store. A caller-supplied `GITEA_TOKEN` retains
|
||||
its established environment precedence.
|
||||
|
||||
**There is no precedence between the two stores and no fallback from one to the other.**
|
||||
A seat whose slot is empty is refused even when a same-named token sits in the framework
|
||||
store. One credential lives in exactly one location: a second copy is drift rather than
|
||||
|
||||
Reference in New Issue
Block a user