Commit 4ffdc2c645

4ffdc2c645a82458594f2b5cf72bf7c87de7b4c2

parent: 8a379d4719

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-09-28 09:03 UTC

wiki: fix API token-refusal claim, batched-review status, watch/pin dispatch, login-link URL exception

Closes #261

Layout: unified · split

.gitbay/wiki/API.org +3 −2
@@ -59,8 +59,9 @@ the command wrote diagnostics:
5959
6060HTTP status maps the exit code: 0→200, 2→400, 3→404, 4→403, else 500.
6161Commands that emit raw text rather than an envelope (=help=, =mr diff=)
62come wrapped as ={"output": "..."}=. Git transport commands and the
63token commands are refused by name.
62come wrapped as ={"output": "..."}=. Git transport commands are refused
63by name; the token commands are not — a full-scope token can mint,
64list and revoke tokens the same way it can run anything else.
6465
6566#+begin_src sh
6667curl -s -H "Authorization: Bearer $TOKEN" \
.gitbay/wiki/Parity.org +12 −7
@@ -80,9 +80,13 @@ does not appear in anyone's review queue. Draft is a flag rather than a
8080fifth state, so every =state = 'open'= rule still means what it did.
8181=mr revisions= lists the heads a merge request has had; the web page
8282lists them beside the reviews they staled, and the iOS client has a
83Revisions section. =mr range-diff= compares two heads: the iOS client
84shows it from a revision to the one before, as text; the web has no
85view. Batched review is not built.
83Revisions section. =mr range-diff= compares two heads: the iOS client shows it from a
84revision to the one before, as text; the web has no view yet
85(krz/gitbay#269). Batched review — draft diff comments held with
86=mr comment --pending= and sent together with =--comment=/=--discard=
87or a verdict — is built and the web uses it: composing review
88comments before publishing them is the same round trip as the CLI's
89=--pending= flag.
8690
8791=mr review request --add <user>= asks a *particular* person, who then
8892carries the merge request in their queue and is notified; =--remove=
@@ -187,7 +191,7 @@ rather than the one the web page shows.
187191| bookmark list | yes | yes | yes |
188192| bookmarks on your profile | n/a | yes | no |
189193| watch, unwatch | yes | yes | yes |
190| mute | yes | no | yes |
194| mute | yes | yes | yes |
191195| settings, protection | yes | yes | yes |
192196| default branch | yes | yes | yes |
193197| merge requests only | yes | yes | yes |
@@ -247,9 +251,10 @@ repository — and a repository bookmarked while public and since made
247251private drops out of the listing rather than leaking that it exists
248252(krz/gitbay#146).
249253
250The web's watch and pin controls write the store directly instead of
251dispatching =repo watch= and =repo pin=. That is why the web cannot
252mute: its toggle knows watching and default only.
254The web's watch and pin controls dispatch =repo pin=/=repo unpin= and
255=repo watch=/=repo mute=/=repo unwatch=, the same commands the CLI runs
256(krz/gitbay#261). The single watch button cycles default, watching and
257muted.
253258
254259Dependency checks are off until a repository's admin turns them on: the
255260check tells a public registry what the repository depends on. =repo deps
.gitbay/wiki/Threat-Model.org +9 −4
@@ -17,10 +17,15 @@ matrix and the open gaps are in the [[file:Architecture/00-Overview.org][Archite
1717- *Serve repository HTML on its own origin as active content.* Raw file
1818 serving is =text/plain= with =nosniff=. Rendered markdown/org is
1919 sanitized (bluemonday) and served under a CSP that forbids scripts.
20- *Put secrets in argv, URLs, or logs.* Import and mirror credentials,
21 registration invites, and API tokens travel on stdin or in request
22 bodies, never as command arguments (visible in =/proc=) or query
23 strings. Tokens are stored only as SHA-256 hashes.
20- *Put secrets in argv, URLs, or logs, with one documented exception.*
21 Import and mirror credentials, registration invites, and API tokens
22 travel on stdin or in request bodies, never as command arguments
23 (visible in =/proc=) or query strings. The one exception is the
24 emailed login link, =/login?token=...=: single-use, 15-minute expiry,
25 and the response that consumes it carries =Cache-Control: no-store= so
26 no intermediary keeps a copy. An operator running gitbay behind a
27 reverse proxy should configure that proxy to strip the query string
28 from its own access logs. Tokens are stored only as SHA-256 hashes.
2429- *Name a mail recipient in the log.* A queued mail is logged by its
2530 queue row id, never by address, and the relay's own error is redacted
2631 before it is logged because a rejection usually quotes the address it
CHANGELOG.org +3
@@ -110,6 +110,9 @@ for the eighteen commands whose CLI path differs from the registry's
110110- The response that consumes a login link's =?token== sends
111111 =Cache-Control: no-store=, so no intermediary keeps a copy of the
112112 single-use URL (#261).
113- Wiki documentation fixes: API.org clarifies token commands work on the
114 API, Parity.org documents batched review and web watch/pin dispatch,
115 Threat-Model.org documents the login-link URL exception (#261).
113116
114117* v1.36.0 — 2026-09-23
115118