Commit 4ffdc2c645
Verified · cmc ci/build: success ci/test: success
Layout: unified · split
.gitbay/wiki/API.org +3 −2
| @@ -59,8 +59,9 @@ the command wrote diagnostics: | |||
| 59 | 59 | ||
| 60 | HTTP status maps the exit code: 0→200, 2→400, 3→404, 4→403, else 500. | 60 | HTTP status maps the exit code: 0→200, 2→400, 3→404, 4→403, else 500. |
| 61 | Commands that emit raw text rather than an envelope (=help=, =mr diff=) | 61 | Commands that emit raw text rather than an envelope (=help=, =mr diff=) |
| 62 | come wrapped as ={"output": "..."}=. Git transport commands and the | 62 | come wrapped as ={"output": "..."}=. Git transport commands are refused |
| 63 | token commands are refused by name. | 63 | by name; the token commands are not — a full-scope token can mint, |
| 64 | list and revoke tokens the same way it can run anything else. | ||
| 64 | 65 | ||
| 65 | #+begin_src sh | 66 | #+begin_src sh |
| 66 | curl -s -H "Authorization: Bearer $TOKEN" \ | 67 | curl -s -H "Authorization: Bearer $TOKEN" \ |
.gitbay/wiki/Parity.org +12 −7
| @@ -80,9 +80,13 @@ does not appear in anyone's review queue. Draft is a flag rather than a | |||
| 80 | fifth state, so every =state = 'open'= rule still means what it did. | 80 | fifth state, so every =state = 'open'= rule still means what it did. |
| 81 | =mr revisions= lists the heads a merge request has had; the web page | 81 | =mr revisions= lists the heads a merge request has had; the web page |
| 82 | lists them beside the reviews they staled, and the iOS client has a | 82 | lists them beside the reviews they staled, and the iOS client has a |
| 83 | Revisions section. =mr range-diff= compares two heads: the iOS client | 83 | Revisions section. =mr range-diff= compares two heads: the iOS client shows it from a |
| 84 | shows it from a revision to the one before, as text; the web has no | 84 | revision to the one before, as text; the web has no view yet |
| 85 | view. Batched review is not built. | 85 | (krz/gitbay#269). Batched review — draft diff comments held with |
| 86 | =mr comment --pending= and sent together with =--comment=/=--discard= | ||
| 87 | or a verdict — is built and the web uses it: composing review | ||
| 88 | comments before publishing them is the same round trip as the CLI's | ||
| 89 | =--pending= flag. | ||
| 86 | 90 | ||
| 87 | =mr review request --add <user>= asks a *particular* person, who then | 91 | =mr review request --add <user>= asks a *particular* person, who then |
| 88 | carries the merge request in their queue and is notified; =--remove= | 92 | carries the merge request in their queue and is notified; =--remove= |
| @@ -187,7 +191,7 @@ rather than the one the web page shows. | |||
| 187 | | bookmark list | yes | yes | yes | | 191 | | bookmark list | yes | yes | yes | |
| 188 | | bookmarks on your profile | n/a | yes | no | | 192 | | bookmarks on your profile | n/a | yes | no | |
| 189 | | watch, unwatch | yes | yes | yes | | 193 | | watch, unwatch | yes | yes | yes | |
| 190 | | mute | yes | no | yes | | 194 | | mute | yes | yes | yes | |
| 191 | | settings, protection | yes | yes | yes | | 195 | | settings, protection | yes | yes | yes | |
| 192 | | default branch | yes | yes | yes | | 196 | | default branch | yes | yes | yes | |
| 193 | | merge requests only | yes | yes | yes | | 197 | | merge requests only | yes | yes | yes | |
| @@ -247,9 +251,10 @@ repository — and a repository bookmarked while public and since made | |||
| 247 | private drops out of the listing rather than leaking that it exists | 251 | private drops out of the listing rather than leaking that it exists |
| 248 | (krz/gitbay#146). | 252 | (krz/gitbay#146). |
| 249 | 253 | ||
| 250 | The web's watch and pin controls write the store directly instead of | 254 | The web's watch and pin controls dispatch =repo pin=/=repo unpin= and |
| 251 | dispatching =repo watch= and =repo pin=. That is why the web cannot | 255 | =repo watch=/=repo mute=/=repo unwatch=, the same commands the CLI runs |
| 252 | mute: its toggle knows watching and default only. | 256 | (krz/gitbay#261). The single watch button cycles default, watching and |
| 257 | muted. | ||
| 253 | 258 | ||
| 254 | Dependency checks are off until a repository's admin turns them on: the | 259 | Dependency checks are off until a repository's admin turns them on: the |
| 255 | check tells a public registry what the repository depends on. =repo deps | 260 | check tells a public registry what the repository depends on. =repo deps |
.gitbay/wiki/Threat-Model.org +9 −4
| @@ -17,10 +17,15 @@ matrix and the open gaps are in the [[file:Architecture/00-Overview.org][Archite | |||
| 17 | - *Serve repository HTML on its own origin as active content.* Raw file | 17 | - *Serve repository HTML on its own origin as active content.* Raw file |
| 18 | serving is =text/plain= with =nosniff=. Rendered markdown/org is | 18 | serving is =text/plain= with =nosniff=. Rendered markdown/org is |
| 19 | sanitized (bluemonday) and served under a CSP that forbids scripts. | 19 | sanitized (bluemonday) and served under a CSP that forbids scripts. |
| 20 | - *Put secrets in argv, URLs, or logs.* Import and mirror credentials, | 20 | - *Put secrets in argv, URLs, or logs, with one documented exception.* |
| 21 | registration invites, and API tokens travel on stdin or in request | 21 | Import and mirror credentials, registration invites, and API tokens |
| 22 | bodies, never as command arguments (visible in =/proc=) or query | 22 | travel on stdin or in request bodies, never as command arguments |
| 23 | strings. Tokens are stored only as SHA-256 hashes. | 23 | (visible in =/proc=) or query strings. The one exception is the |
| 24 | emailed login link, =/login?token=...=: single-use, 15-minute expiry, | ||
| 25 | and the response that consumes it carries =Cache-Control: no-store= so | ||
| 26 | no intermediary keeps a copy. An operator running gitbay behind a | ||
| 27 | reverse proxy should configure that proxy to strip the query string | ||
| 28 | from its own access logs. Tokens are stored only as SHA-256 hashes. | ||
| 24 | - *Name a mail recipient in the log.* A queued mail is logged by its | 29 | - *Name a mail recipient in the log.* A queued mail is logged by its |
| 25 | queue row id, never by address, and the relay's own error is redacted | 30 | queue row id, never by address, and the relay's own error is redacted |
| 26 | before it is logged because a rejection usually quotes the address it | 31 | before it is logged because a rejection usually quotes the address it |
CHANGELOG.org +3
| @@ -110,6 +110,9 @@ for the eighteen commands whose CLI path differs from the registry's | |||
| 110 | - The response that consumes a login link's =?token== sends | 110 | - The response that consumes a login link's =?token== sends |
| 111 | =Cache-Control: no-store=, so no intermediary keeps a copy of the | 111 | =Cache-Control: no-store=, so no intermediary keeps a copy of the |
| 112 | single-use URL (#261). | 112 | single-use URL (#261). |
| 113 | - Wiki documentation fixes: API.org clarifies token commands work on the | ||
| 114 | API, Parity.org documents batched review and web watch/pin dispatch, | ||
| 115 | Threat-Model.org documents the login-link URL exception (#261). | ||
| 113 | 116 | ||
| 114 | * v1.36.0 — 2026-09-23 | 117 | * v1.36.0 — 2026-09-23 |
| 115 | 118 | ||