Files
stack/agents/sage/work/gitea-setup/verify.mjs
T
jason.woltjeandClaude Opus 5.5 5fe6a051d2 docs(slice1): runbook section 1 run through the Gitea admin API (row 35, #1517, lead decision 74)
Jason ruled that agents run the steps his admin grant to the jarvis
Gitea token covers. Sage created the four mosaic-stack bots (ids
114-117, restricted, non-admin), added them as collaborators (W/W/W/R),
and minted one scoped token each (ids 191-194). The tokens were written
0600 outside the repo. Scripts and receipt are in
agents/sage/work/gitea-setup/. The guide and SR brief now say who
runs which section. Sections 2 to 4 (Vikunja) stay with Jason.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-09 17:25:08 -05:00

21 lines
1.2 KiB
JavaScript

// Probe each bot token: identity, repo permission, and refusals. Prints statuses only.
import fs from "node:fs";
import os from "node:os";
const BASE = "https://git.mosaicstack.dev/api/v1";
const S = `${os.homedir()}/.config/mosaic-dev/secrets/mosaic-stack`;
const roles = process.argv.slice(2).length ? process.argv.slice(2) : ["pm", "cto", "coder", "reviewer"];
for (const r of roles) {
const tok = fs.readFileSync(`${S}/${r}-gitea.token`, "utf8");
const h = { Authorization: `token ${tok}`, Accept: "application/json" };
const get = async (p) => { const res = await fetch(`${BASE}/${p}`, { headers: h }); let j = null; try { j = await res.json(); } catch {} return { s: res.status, j }; };
const me = await get("user");
const repo = await get("repos/mosaicstack/stack");
const issue = await get("repos/mosaicstack/stack/issues?limit=1");
const admin = await get("admin/users?limit=1");
const org = await get("orgs/mosaicstack/repos?limit=50");
const p = repo.j?.permissions || {};
console.log(`${r}: user=${me.s} login=${me.j?.login} admin=${me.j?.is_admin} | repo=${repo.s} push=${p.push} admin=${p.admin} pull=${p.pull} | issues=${issue.s} | admin/users=${admin.s} | org repos=${org.s} n=${Array.isArray(org.j) ? org.j.length : "-"}`);
}