Commit 4ffdc2c645
4ffdc2c645a82458594f2b5cf72bf7c87de7b4c2
parent: 8a379d4719
Verified · cmc ci/build: success ci/test: success
cmc <hello@cleberg.net> · 2026-09-28 09:03 UTC
wiki: fix API token-refusal claim, batched-review status, watch/pin dispatch, login-link URL exception
Closes #261
Layout: unified · split
.gitbay/wiki/API.org
+3 −2
| @@ -59,8 +59,9 @@ the command wrote diagnostics: |
| 59 | 59 | |
| 60 | 60 | HTTP status maps the exit code: 0→200, 2→400, 3→404, 4→403, else 500. |
| 61 | 61 | Commands that emit raw text rather than an envelope (=help=, =mr diff=) |
| 62 | | come wrapped as ={"output": "..."}=. Git transport commands and the |
| 63 | | token commands are refused by name. |
| 62 | come wrapped as ={"output": "..."}=. Git transport commands are refused |
| 63 | by name; the token commands are not — a full-scope token can mint, |
| 64 | list and revoke tokens the same way it can run anything else. |
| 64 | 65 | |
| 65 | 66 | #+begin_src sh |
| 66 | 67 | curl -s -H "Authorization: Bearer $TOKEN" \ |
.gitbay/wiki/Parity.org
+12 −7
| @@ -80,9 +80,13 @@ does not appear in anyone's review queue. Draft is a flag rather than a |
| 80 | 80 | fifth state, so every =state = 'open'= rule still means what it did. |
| 81 | 81 | =mr revisions= lists the heads a merge request has had; the web page |
| 82 | 82 | lists them beside the reviews they staled, and the iOS client has a |
| 83 | | Revisions section. =mr range-diff= compares two heads: the iOS client |
| 84 | | shows it from a revision to the one before, as text; the web has no |
| 85 | | view. Batched review is not built. |
| 83 | Revisions section. =mr range-diff= compares two heads: the iOS client shows it from a |
| 84 | revision to the one before, as text; the web has no view yet |
| 85 | (krz/gitbay#269). Batched review — draft diff comments held with |
| 86 | =mr comment --pending= and sent together with =--comment=/=--discard= |
| 87 | or a verdict — is built and the web uses it: composing review |
| 88 | comments before publishing them is the same round trip as the CLI's |
| 89 | =--pending= flag. |
| 86 | 90 | |
| 87 | 91 | =mr review request --add <user>= asks a *particular* person, who then |
| 88 | 92 | carries the merge request in their queue and is notified; =--remove= |
| @@ -187,7 +191,7 @@ rather than the one the web page shows. |
| 187 | 191 | | bookmark list | yes | yes | yes | |
| 188 | 192 | | bookmarks on your profile | n/a | yes | no | |
| 189 | 193 | | watch, unwatch | yes | yes | yes | |
| 190 | | | mute | yes | no | yes | |
| 194 | | mute | yes | yes | yes | |
| 191 | 195 | | settings, protection | yes | yes | yes | |
| 192 | 196 | | default branch | yes | yes | yes | |
| 193 | 197 | | merge requests only | yes | yes | yes | |
| @@ -247,9 +251,10 @@ repository — and a repository bookmarked while public and since made |
| 247 | 251 | private drops out of the listing rather than leaking that it exists |
| 248 | 252 | (krz/gitbay#146). |
| 249 | 253 | |
| 250 | | The web's watch and pin controls write the store directly instead of |
| 251 | | dispatching =repo watch= and =repo pin=. That is why the web cannot |
| 252 | | mute: its toggle knows watching and default only. |
| 254 | The web's watch and pin controls dispatch =repo pin=/=repo unpin= and |
| 255 | =repo watch=/=repo mute=/=repo unwatch=, the same commands the CLI runs |
| 256 | (krz/gitbay#261). The single watch button cycles default, watching and |
| 257 | muted. |
| 253 | 258 | |
| 254 | 259 | Dependency checks are off until a repository's admin turns them on: the |
| 255 | 260 | check tells a public registry what the repository depends on. =repo deps |
.gitbay/wiki/Threat-Model.org
+9 −4
| @@ -17,10 +17,15 @@ matrix and the open gaps are in the [[file:Architecture/00-Overview.org][Archite |
| 17 | 17 | - *Serve repository HTML on its own origin as active content.* Raw file |
| 18 | 18 | serving is =text/plain= with =nosniff=. Rendered markdown/org is |
| 19 | 19 | sanitized (bluemonday) and served under a CSP that forbids scripts. |
| 20 | | - *Put secrets in argv, URLs, or logs.* Import and mirror credentials, |
| 21 | | registration invites, and API tokens travel on stdin or in request |
| 22 | | bodies, never as command arguments (visible in =/proc=) or query |
| 23 | | strings. Tokens are stored only as SHA-256 hashes. |
| 20 | - *Put secrets in argv, URLs, or logs, with one documented exception.* |
| 21 | Import and mirror credentials, registration invites, and API tokens |
| 22 | travel on stdin or in request bodies, never as command arguments |
| 23 | (visible in =/proc=) or query strings. The one exception is the |
| 24 | emailed login link, =/login?token=...=: single-use, 15-minute expiry, |
| 25 | and the response that consumes it carries =Cache-Control: no-store= so |
| 26 | no intermediary keeps a copy. An operator running gitbay behind a |
| 27 | reverse proxy should configure that proxy to strip the query string |
| 28 | from its own access logs. Tokens are stored only as SHA-256 hashes. |
| 24 | 29 | - *Name a mail recipient in the log.* A queued mail is logged by its |
| 25 | 30 | queue row id, never by address, and the relay's own error is redacted |
| 26 | 31 | before it is logged because a rejection usually quotes the address it |
CHANGELOG.org
+3
| @@ -110,6 +110,9 @@ for the eighteen commands whose CLI path differs from the registry's |
| 110 | 110 | - The response that consumes a login link's =?token== sends |
| 111 | 111 | =Cache-Control: no-store=, so no intermediary keeps a copy of the |
| 112 | 112 | single-use URL (#261). |
| 113 | - Wiki documentation fixes: API.org clarifies token commands work on the |
| 114 | API, Parity.org documents batched review and web watch/pin dispatch, |
| 115 | Threat-Model.org documents the login-link URL exception (#261). |
| 113 | 116 | |
| 114 | 117 | * v1.36.0 — 2026-09-23 |
| 115 | 118 | |