Commit 08a24a6e68

08a24a6e68d86f3dfd13c88a8125b580b1dc614b

parent: 879ef3991c

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-09-29 02:32 UTC

control: admin repo visibility needs a recent web sign-in

Ref #297

Layout: unified · split

CHANGELOG.org +2 −1
@@ -25,7 +25,8 @@ anything beyond "replace the binary and restart" is needed.
25- A browser session creates credentials and grants access — keys, PGP 25- A browser session creates credentials and grants access — keys, PGP
26 keys, tokens, verified addresses, org and repository roles, transfers, 26 keys, tokens, verified addresses, org and repository roles, transfers,
27 repository visibility, webhooks, secrets, mirrors, and the admin 27 repository visibility, webhooks, secrets, mirrors, and the admin
28 promote/enable actions — only within 15 minutes of signing in. An 28 promote/enable and repository-visibility actions — only within 15
29 minutes of signing in. An
29 older session gets the form back with a "Sign in again" link, and the 30 older session gets the form back with a "Sign in again" link, and the
30 login returns to it. SSH and API tokens are unaffected (#297). 31 login returns to it. SSH and API tokens are unaffected (#297).
31- The builds page's status badge section gives an org-mode snippet 32- The builds page's status badge section gives an org-mode snippet
internal/control/admin.go +5 −4
@@ -80,10 +80,11 @@ func init() {
80 Examples: []string{"admin repo unarchive alice/old-project"}, 80 Examples: []string{"admin repo unarchive alice/old-project"},
81 Run: runAdminRepoUnarchive}) 81 Run: runAdminRepoUnarchive})
82 register(Command{Path: []string{"admin", "repo", "visibility"}, 82 register(Command{Path: []string{"admin", "repo", "visibility"},
83 Summary: "set any repository's visibility (instance admins; audited)", 83 NeedsRecentSignIn: true,
84 Usage: "admin repo visibility <owner/name> public|private", 84 Summary: "set any repository's visibility (instance admins; audited)",
85 Examples: []string{"admin repo visibility alice/secret private"}, 85 Usage: "admin repo visibility <owner/name> public|private",
86 Run: runAdminRepoVisibility}) 86 Examples: []string{"admin repo visibility alice/secret private"},
87 Run: runAdminRepoVisibility})
87 register(Command{Path: []string{"admin", "repo", "delete"}, 88 register(Command{Path: []string{"admin", "repo", "delete"},
88 Summary: "delete any repository (instance admins; audited)", 89 Summary: "delete any repository (instance admins; audited)",
89 Usage: "admin repo delete <owner/name> --yes", 90 Usage: "admin repo delete <owner/name> --yes",
internal/control/reauth_test.go +1
@@ -109,6 +109,7 @@ func TestNeedsRecentSignInSet(t *testing.T) {
109 want := []string{ 109 want := []string{
110 "admin email verify", 110 "admin email verify",
111 "admin invite", 111 "admin invite",
112 "admin repo visibility",
112 "admin user create", 113 "admin user create",
113 "admin user enable", 114 "admin user enable",
114 "admin user promote", 115 "admin user promote",