Jason ruled that agents run the steps his admin grant to the jarvis Gitea token covers. Sage created the four mosaic-stack bots (ids 114-117, restricted, non-admin), added them as collaborators (W/W/W/R), and minted one scoped token each (ids 191-194). The tokens were written 0600 outside the repo. Scripts and receipt are in agents/sage/work/gitea-setup/. The guide and SR brief now say who runs which section. Sections 2 to 4 (Vikunja) stay with Jason. Co-Authored-By: Claude Opus 5.5 <[email protected]>
21 lines
1.2 KiB
JavaScript
21 lines
1.2 KiB
JavaScript
// Probe each bot token: identity, repo permission, and refusals. Prints statuses only.
|
|
import fs from "node:fs";
|
|
import os from "node:os";
|
|
|
|
const BASE = "https://git.mosaicstack.dev/api/v1";
|
|
const S = `${os.homedir()}/.config/mosaic-dev/secrets/mosaic-stack`;
|
|
const roles = process.argv.slice(2).length ? process.argv.slice(2) : ["pm", "cto", "coder", "reviewer"];
|
|
|
|
for (const r of roles) {
|
|
const tok = fs.readFileSync(`${S}/${r}-gitea.token`, "utf8");
|
|
const h = { Authorization: `token ${tok}`, Accept: "application/json" };
|
|
const get = async (p) => { const res = await fetch(`${BASE}/${p}`, { headers: h }); let j = null; try { j = await res.json(); } catch {} return { s: res.status, j }; };
|
|
const me = await get("user");
|
|
const repo = await get("repos/mosaicstack/stack");
|
|
const issue = await get("repos/mosaicstack/stack/issues?limit=1");
|
|
const admin = await get("admin/users?limit=1");
|
|
const org = await get("orgs/mosaicstack/repos?limit=50");
|
|
const p = repo.j?.permissions || {};
|
|
console.log(`${r}: user=${me.s} login=${me.j?.login} admin=${me.j?.is_admin} | repo=${repo.s} push=${p.push} admin=${p.admin} pull=${p.pull} | issues=${issue.s} | admin/users=${admin.s} | org repos=${org.s} n=${Array.isArray(org.j) ? org.j.length : "-"}`);
|
|
}
|