docs(records): lead decision 37, raw per-seat token files in the Gitea helper (row 12)
Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
@@ -473,3 +473,26 @@ which stay with him. Each item names who decided it and what happened.
|
|||||||
(24 pass, 2 fail). The canonical checkout passes 26/26. This goes
|
(24 pass, 2 fail). The canonical checkout passes 26/26. This goes
|
||||||
to DEFERRED for Darkwing. Until it is fixed, read the queue suite's
|
to DEFERRED for Darkwing. Until it is fixed, read the queue suite's
|
||||||
result in the canonical checkout.
|
result in the canonical checkout.
|
||||||
|
37. **Gitea helper reads the per-seat raw token files (row 12).**
|
||||||
|
Darkwing found that `scripts/gitea-api.sh` accepts only the JSON
|
||||||
|
credential file, while the per-seat files Jason ruled on hold a raw
|
||||||
|
token (checked with `stat` only: 41 bytes for four seats, 40 for
|
||||||
|
jarvis, all 0600). Without a change every live Piece D attempt fails
|
||||||
|
at the pre-send `GET user`. Sage says yes to a separate helper patch
|
||||||
|
with the D candidate, on these terms:
|
||||||
|
- The JSON path is unchanged. The raw path applies only when the file
|
||||||
|
isn't JSON.
|
||||||
|
- The raw path accepts exactly one line of token characters, with an
|
||||||
|
optional trailing newline, and refuses anything else before any
|
||||||
|
request.
|
||||||
|
- On the raw path the base URL is fixed at https://git.mosaicstack.dev,
|
||||||
|
with no override.
|
||||||
|
- The file checks stay (regular file, no symlink, no group or other
|
||||||
|
bits). The token goes only through the curl config stream. Tests
|
||||||
|
use stubs and read no real token.
|
||||||
|
- A seat uses only its own file.
|
||||||
|
- Rocko reviews the patch as well as Filbert.
|
||||||
|
This doesn't widen access: each seat already has the token by Jason's
|
||||||
|
ruling, and the change only lets the helper read the file's actual
|
||||||
|
format. JSON wrapper files would need writes under `~/.mosaic`, which
|
||||||
|
are forbidden.
|
||||||
|
|||||||
Reference in New Issue
Block a user