Commit 828f1af8fc

828f1af8fcc0cd86702c1294c0f51c6eab4f1e5e

parent: ce4473b8e1

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-28 19:05 UTC

Document profiles

Users had no profile section at all; profile show/set and org profile
were undocumented, not just the new about and links fields.

Corrects the Parity note from the previous commit: profile set is not
SSHOnly, so the API can run it — the web and iOS columns are no for want
of a form, not by rule. Extends the tracking-pixel residual risk to
profile about text.

Layout: unified · split

Parity.org +4 −3
@@ -133,9 +133,10 @@ so it ignores =about= and =links= rather than breaking on them.
133133| account export bundle | yes | no | no |
134134| profile set | yes | no | no |
135135
136=profile set= carries description, website, about and links. Editing a
137profile has always been SSH-only; nothing about it is a credential,
138so this is a gap rather than a rule.
136=profile set= carries description, website, about and links. It is not
137=SSHOnly= — nothing about a bio is a credential, and the JSON API runs
138it — but no surface has ever offered a form, so the =no= above is
139missing UI rather than a rule.
139140
140141* Organizations
141142
Threat-Model.org +5 −3
@@ -82,9 +82,11 @@ JavaScript, so =script-src 'none'= costs nothing.
8282
8383* Residual risks, accepted
8484
85- External images in rendered READMEs load from their origin (no image
86 proxy), which a repo author can use as a tracking pixel against a
87 viewer. Documented; proxying is future work.
85- External images in rendered READMEs and profile about text load from
86 their origin (no image proxy), which the author can use as a tracking
87 pixel against a viewer. A profile is the wider surface of the two: it
88 is linked from every commit and issue its owner touches. Documented;
89 proxying is future work.
8890- Backups are consistent per the DB-snapshot-first ordering but are not a
8991 single atomic snapshot; a few orphaned git objects are possible and
9092 harmless (see [[Admin]]).
Users.org +42
@@ -87,6 +87,48 @@ key, author line claims someone else), =signed_key_expired= /
8787(web edits, merge commits) are always =unsigned= — the server holds no
8888signing key on principle.
8989
90* Profiles
91
92A profile is what =/{owner}= shows: a one-line description, a website, a
93set of links, long-form about text, the repositories you can see, org
94membership, and a year of activity. Users and orgs have the same fields.
95
96#+begin_src sh
97gitbay profile show # your own
98gitbay profile show alice
99gitbay profile set --description "builds small tools" --website https://alice.example
100#+end_src
101
102About text is markdown by default, or org-mode. It takes inline text or
103stdin, so it can live in a file you keep:
104
105#+begin_src sh
106gitbay profile set --about "I maintain a few small tools."
107gitbay profile set --file - --about-format org < about.org
108#+end_src
109
110Up to five links, each =label|url= or a bare url, http(s) only. Passing
111=--link= replaces the whole set; a single empty one clears it:
112
113#+begin_src sh
114gitbay profile set --link "Mastodon|https://fosstodon.example/@alice" \
115 --link https://alice.example/now
116gitbay profile set --link "" # clear
117#+end_src
118
119Every field follows the same rule as the rest of the CLI: a flag you
120leave out is untouched, and ='' clears the one you name. Org profiles
121work the same way and need org admin:
122
123#+begin_src sh
124gitbay org profile krz --description "software and experiments" --about-format org --file - < krz.org
125gitbay org profile krz # no flags shows it
126#+end_src
127
128The web renders profiles but has no form for editing one, so the CLI is
129the only interface today. =profile set= is not =SSHOnly=, so the JSON API
130runs it like any other write command.
131
90132* Repositories
91133
92134#+begin_src sh