Commit 4ffdc2c645

4ffdc2c645a82458594f2b5cf72bf7c87de7b4c2

parent: 8a379d4719

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-09-28 09:03 UTC

wiki: fix API token-refusal claim, batched-review status, watch/pin dispatch, login-link URL exception

Closes #261

Layout: unified · split

.gitbay/wiki/API.org +3 −2
@@ -59,8 +59,9 @@ the command wrote diagnostics:
59 59
60HTTP status maps the exit code: 0→200, 2→400, 3→404, 4→403, else 500. 60HTTP status maps the exit code: 0→200, 2→400, 3→404, 4→403, else 500.
61Commands that emit raw text rather than an envelope (=help=, =mr diff=) 61Commands that emit raw text rather than an envelope (=help=, =mr diff=)
62come wrapped as ={"output": "..."}=. Git transport commands and the 62come wrapped as ={"output": "..."}=. Git transport commands are refused
63token commands are refused by name. 63by name; the token commands are not — a full-scope token can mint,
64list and revoke tokens the same way it can run anything else.
64 65
65#+begin_src sh 66#+begin_src sh
66curl -s -H "Authorization: Bearer $TOKEN" \ 67curl -s -H "Authorization: Bearer $TOKEN" \
.gitbay/wiki/Parity.org +12 −7
@@ -80,9 +80,13 @@ does not appear in anyone's review queue. Draft is a flag rather than a
80fifth state, so every =state = 'open'= rule still means what it did. 80fifth state, so every =state = 'open'= rule still means what it did.
81=mr revisions= lists the heads a merge request has had; the web page 81=mr revisions= lists the heads a merge request has had; the web page
82lists them beside the reviews they staled, and the iOS client has a 82lists them beside the reviews they staled, and the iOS client has a
83Revisions section. =mr range-diff= compares two heads: the iOS client 83Revisions section. =mr range-diff= compares two heads: the iOS client shows it from a
84shows it from a revision to the one before, as text; the web has no 84revision to the one before, as text; the web has no view yet
85view. Batched review is not built. 85(krz/gitbay#269). Batched review — draft diff comments held with
86=mr comment --pending= and sent together with =--comment=/=--discard=
87or a verdict — is built and the web uses it: composing review
88comments before publishing them is the same round trip as the CLI's
89=--pending= flag.
86 90
87=mr review request --add <user>= asks a *particular* person, who then 91=mr review request --add <user>= asks a *particular* person, who then
88carries the merge request in their queue and is notified; =--remove= 92carries the merge request in their queue and is notified; =--remove=
@@ -187,7 +191,7 @@ rather than the one the web page shows.
187| bookmark list | yes | yes | yes | 191| bookmark list | yes | yes | yes |
188| bookmarks on your profile | n/a | yes | no | 192| bookmarks on your profile | n/a | yes | no |
189| watch, unwatch | yes | yes | yes | 193| watch, unwatch | yes | yes | yes |
190| mute | yes | no | yes | 194| mute | yes | yes | yes |
191| settings, protection | yes | yes | yes | 195| settings, protection | yes | yes | yes |
192| default branch | yes | yes | yes | 196| default branch | yes | yes | yes |
193| merge requests only | yes | yes | yes | 197| merge requests only | yes | yes | yes |
@@ -247,9 +251,10 @@ repository — and a repository bookmarked while public and since made
247private drops out of the listing rather than leaking that it exists 251private drops out of the listing rather than leaking that it exists
248(krz/gitbay#146). 252(krz/gitbay#146).
249 253
250The web's watch and pin controls write the store directly instead of 254The web's watch and pin controls dispatch =repo pin=/=repo unpin= and
251dispatching =repo watch= and =repo pin=. That is why the web cannot 255=repo watch=/=repo mute=/=repo unwatch=, the same commands the CLI runs
252mute: its toggle knows watching and default only. 256(krz/gitbay#261). The single watch button cycles default, watching and
257muted.
253 258
254Dependency checks are off until a repository's admin turns them on: the 259Dependency checks are off until a repository's admin turns them on: the
255check tells a public registry what the repository depends on. =repo deps 260check tells a public registry what the repository depends on. =repo deps
.gitbay/wiki/Threat-Model.org +9 −4
@@ -17,10 +17,15 @@ matrix and the open gaps are in the [[file:Architecture/00-Overview.org][Archite
17- *Serve repository HTML on its own origin as active content.* Raw file 17- *Serve repository HTML on its own origin as active content.* Raw file
18 serving is =text/plain= with =nosniff=. Rendered markdown/org is 18 serving is =text/plain= with =nosniff=. Rendered markdown/org is
19 sanitized (bluemonday) and served under a CSP that forbids scripts. 19 sanitized (bluemonday) and served under a CSP that forbids scripts.
20- *Put secrets in argv, URLs, or logs.* Import and mirror credentials, 20- *Put secrets in argv, URLs, or logs, with one documented exception.*
21 registration invites, and API tokens travel on stdin or in request 21 Import and mirror credentials, registration invites, and API tokens
22 bodies, never as command arguments (visible in =/proc=) or query 22 travel on stdin or in request bodies, never as command arguments
23 strings. Tokens are stored only as SHA-256 hashes. 23 (visible in =/proc=) or query strings. The one exception is the
24 emailed login link, =/login?token=...=: single-use, 15-minute expiry,
25 and the response that consumes it carries =Cache-Control: no-store= so
26 no intermediary keeps a copy. An operator running gitbay behind a
27 reverse proxy should configure that proxy to strip the query string
28 from its own access logs. Tokens are stored only as SHA-256 hashes.
24- *Name a mail recipient in the log.* A queued mail is logged by its 29- *Name a mail recipient in the log.* A queued mail is logged by its
25 queue row id, never by address, and the relay's own error is redacted 30 queue row id, never by address, and the relay's own error is redacted
26 before it is logged because a rejection usually quotes the address it 31 before it is logged because a rejection usually quotes the address it
CHANGELOG.org +3
@@ -110,6 +110,9 @@ for the eighteen commands whose CLI path differs from the registry's
110- The response that consumes a login link's =?token== sends 110- The response that consumes a login link's =?token== sends
111 =Cache-Control: no-store=, so no intermediary keeps a copy of the 111 =Cache-Control: no-store=, so no intermediary keeps a copy of the
112 single-use URL (#261). 112 single-use URL (#261).
113- Wiki documentation fixes: API.org clarifies token commands work on the
114 API, Parity.org documents batched review and web watch/pin dispatch,
115 Threat-Model.org documents the login-link URL exception (#261).
113 116
114* v1.36.0 — 2026-09-23 117* v1.36.0 — 2026-09-23
115 118