Commit 5ff54cce22

5ff54cce2270baa1d85465c840b13cf03973e0d4

parent: a869e55ced

Verified · cmc ci/build: success ci/test: skipped

cmc <hello@cleberg.net> · 2026-09-07 16:43 UTC

Parity: audit against the registry and the iOS client

Split the bookmark row: the iOS client has no bookmark list. Add rows
for revisions, range-diff, issue templates, milestone management,
require-codeowners, access grants, webhooks, remote import, release
assets, the account import bundle and org profile. Fix the stacked and
range-diff prose, and note that the web's watch and pin toggles bypass
the registry.

Layout: unified · split

.gitbay/wiki/Parity.org +30 −6
@@ -50,6 +50,8 @@ browser-only and the iOS build screen unable to say more than the log.
5050| request a review | yes | yes | yes |
5151| choose body markup | yes | yes | yes |
5252| stacked merge requests | yes | yes | yes |
53| revisions | yes | yes | no |
54| range-diff | yes | no | no |
5355
5456Reviews and checks carry the time they last said something, and a
5557=ci/<job>= check carries how long its build ran, so a merge request
@@ -65,13 +67,17 @@ branch is stacked on it: =mr show= and the page say so both ways, and
6567when the lower one merges, everything stacked on it is retargeted onto
6668what it merged into with its reviews kept. A squash or rebase merge is
6769refused while anything is stacked on the merge request, since it would
68rewrite the commits the stack builds on. The iOS client renders the
69retarget but has no stack view yet.
70rewrite the commits the stack builds on. All three surfaces show the
71stack both ways.
7072
7173A draft merge request is open but not asking: it does not merge, and it
7274does not appear in anyone's review queue. Draft is a flag rather than a
7375fifth state, so every =state = 'open'= rule still means what it did.
74Batched review and range-diff (krz/gitbay#111) are not built.
76=mr revisions= lists the heads a merge request has had, and the web
77page lists them beside the reviews they staled; the iOS client shows
78threads left on an earlier revision but not the heads. =mr range-diff=
79compares two heads and has no web or iOS view. Batched review is not
80built.
7581
7682=mr review request --add <user>= asks a *particular* person, who then
7783carries the merge request in their queue and is notified; =--remove=
@@ -104,6 +110,8 @@ reviews, since an approval was of the diff against the old branch.
104110| milestone list | yes | yes | yes |
105111| labels: list, colour | yes | yes | yes |
106112| choose body markup | yes | yes | yes |
113| issue templates | yes | yes | no |
114| milestone create, close, reopen | yes | no | no |
107115
108116Labels are created on the fly by =issue label --add= and managed by
109117=label list=, =label set <label> --color rrggbb= and =label remove=,
@@ -141,10 +149,15 @@ always markdown.
141149| create | yes | yes | yes |
142150| fork | yes | yes | yes |
143151| pin | yes | yes | yes |
144| bookmark, bookmark list | yes | yes | yes |
152| bookmark | yes | yes | yes |
153| bookmark list | yes | yes | no |
145154| watch, unwatch | yes | yes | yes |
146155| mute | yes | no | yes |
147156| settings, protection | yes | yes | yes |
157| require codeowners | yes | yes | no |
158| access grants | yes | no | no |
159| webhooks | yes | no | no |
160| import from a remote | yes | no | no |
148161| topics, website | yes | yes | yes |
149162| visibility | yes | yes | yes |
150163| archive (read-only flag) | yes | yes | yes |
@@ -161,6 +174,8 @@ always markdown.
161174| dependency status | yes | yes | yes |
162175| delete, transfer | yes | no | no |
163176| release delete | yes | yes | yes |
177| release asset add | yes | no | n/a |
178| release asset remove | yes | no | no |
164179
165180No row is web-only any more. Blame, file editing, log at a ref,
166181archive, the public listing and the wiki were all in that state — a
@@ -182,6 +197,10 @@ repository — and a repository bookmarked while public and since made
182197private drops out of the listing rather than leaking that it exists
183198(krz/gitbay#146).
184199
200The web's watch and pin controls write the store directly instead of
201dispatching =repo watch= and =repo pin=. That is why the web cannot
202mute: its toggle knows watching and default only.
203
185204Dependency checks are off until a repository's admin turns them on: the
186205check tells a public registry what the repository depends on. =repo deps
187206status= lists what is behind; the repository's settings page renders the
@@ -202,7 +221,9 @@ missing from it. Archive download is =n/a= on iOS: the read API carries
202221a command's stdout as a JSON string, so a gzip stream cannot survive it,
203222and the app has nowhere useful to put a tarball — the brief rules out
204223local git, so there is no clone, checkout or build to feed. The web's
205route stays the way to get one.
224route stays the way to get one. =release asset add= is =n/a= on iOS for
225the same reason from the other direction: the file arrives on stdin,
226which the API carries as a JSON string.
206227
207228A README or wiki page's org renders per surface: the web through
208229go-org, the iOS client through the shared OrgSwift package
@@ -258,6 +279,7 @@ client has no use for one (krz/gitbay#57).
258279| account export bundle | yes | yes | n/a |
259280| profile set | yes | yes | yes |
260281| request a login link | n/a | yes | n/a |
282| account import bundle | yes | no | n/a |
261283
262284Notifications land in an inbox row per recipient whether or not the
263285instance sends mail, and mail is the second half when SMTP is
@@ -303,6 +325,7 @@ cleared.
303325| team repo grants | yes | yes | yes |
304326| create, rename | yes | yes | yes |
305327| delete | yes | n/a | n/a |
328| profile | yes | no | no |
306329
307330* Pagination
308331
@@ -315,7 +338,8 @@ with the same cursors; iOS pages with them too.
315338* SSH only, by design
316339
317340Build secrets, mirror configuration and tokens, custom domain claims,
318API token minting, deploy keys, account and instance administration. Deleting or transferring a repository is also
341API token minting, web session listing and revocation, deploy keys,
342account and instance administration. Deleting or transferring a repository is also
319343CLI-only, as is deleting an organization: each wants a typed
320344confirmation, not a button.
321345