Commit 828f1af8fc
828f1af8fcc0cd86702c1294c0f51c6eab4f1e5e
parent: ce4473b8e1
Verified · cmc
cmc <hello@cleberg.net> · 2026-08-28 19:05 UTC
Document profiles
Users had no profile section at all; profile show/set and org profile
were undocumented, not just the new about and links fields.
Corrects the Parity note from the previous commit: profile set is not
SSHOnly, so the API can run it — the web and iOS columns are no for want
of a form, not by rule. Extends the tracking-pixel residual risk to
profile about text.
Layout: unified · split
Parity.org
+4 −3
| @@ -133,9 +133,10 @@ so it ignores =about= and =links= rather than breaking on them. |
| 133 | 133 | | account export bundle | yes | no | no | |
| 134 | 134 | | profile set | yes | no | no | |
| 135 | 135 | |
| 136 | | =profile set= carries description, website, about and links. Editing a |
| 137 | | profile has always been SSH-only; nothing about it is a credential, |
| 138 | | so this is a gap rather than a rule. |
| 136 | =profile set= carries description, website, about and links. It is not |
| 137 | =SSHOnly= — nothing about a bio is a credential, and the JSON API runs |
| 138 | it — but no surface has ever offered a form, so the =no= above is |
| 139 | missing UI rather than a rule. |
| 139 | 140 | |
| 140 | 141 | * Organizations |
| 141 | 142 | |
Threat-Model.org
+5 −3
| @@ -82,9 +82,11 @@ JavaScript, so =script-src 'none'= costs nothing. |
| 82 | 82 | |
| 83 | 83 | * Residual risks, accepted |
| 84 | 84 | |
| 85 | | - External images in rendered READMEs load from their origin (no image |
| 86 | | proxy), which a repo author can use as a tracking pixel against a |
| 87 | | viewer. Documented; proxying is future work. |
| 85 | - External images in rendered READMEs and profile about text load from |
| 86 | their origin (no image proxy), which the author can use as a tracking |
| 87 | pixel against a viewer. A profile is the wider surface of the two: it |
| 88 | is linked from every commit and issue its owner touches. Documented; |
| 89 | proxying is future work. |
| 88 | 90 | - Backups are consistent per the DB-snapshot-first ordering but are not a |
| 89 | 91 | single atomic snapshot; a few orphaned git objects are possible and |
| 90 | 92 | harmless (see [[Admin]]). |
Users.org
+42
| @@ -87,6 +87,48 @@ key, author line claims someone else), =signed_key_expired= / |
| 87 | 87 | (web edits, merge commits) are always =unsigned= — the server holds no |
| 88 | 88 | signing key on principle. |
| 89 | 89 | |
| 90 | * Profiles |
| 91 | |
| 92 | A profile is what =/{owner}= shows: a one-line description, a website, a |
| 93 | set of links, long-form about text, the repositories you can see, org |
| 94 | membership, and a year of activity. Users and orgs have the same fields. |
| 95 | |
| 96 | #+begin_src sh |
| 97 | gitbay profile show # your own |
| 98 | gitbay profile show alice |
| 99 | gitbay profile set --description "builds small tools" --website https://alice.example |
| 100 | #+end_src |
| 101 | |
| 102 | About text is markdown by default, or org-mode. It takes inline text or |
| 103 | stdin, so it can live in a file you keep: |
| 104 | |
| 105 | #+begin_src sh |
| 106 | gitbay profile set --about "I maintain a few small tools." |
| 107 | gitbay profile set --file - --about-format org < about.org |
| 108 | #+end_src |
| 109 | |
| 110 | Up to five links, each =label|url= or a bare url, http(s) only. Passing |
| 111 | =--link= replaces the whole set; a single empty one clears it: |
| 112 | |
| 113 | #+begin_src sh |
| 114 | gitbay profile set --link "Mastodon|https://fosstodon.example/@alice" \ |
| 115 | --link https://alice.example/now |
| 116 | gitbay profile set --link "" # clear |
| 117 | #+end_src |
| 118 | |
| 119 | Every field follows the same rule as the rest of the CLI: a flag you |
| 120 | leave out is untouched, and ='' clears the one you name. Org profiles |
| 121 | work the same way and need org admin: |
| 122 | |
| 123 | #+begin_src sh |
| 124 | gitbay org profile krz --description "software and experiments" --about-format org --file - < krz.org |
| 125 | gitbay org profile krz # no flags shows it |
| 126 | #+end_src |
| 127 | |
| 128 | The web renders profiles but has no form for editing one, so the CLI is |
| 129 | the only interface today. =profile set= is not =SSHOnly=, so the JSON API |
| 130 | runs it like any other write command. |
| 131 | |
| 90 | 132 | * Repositories |
| 91 | 133 | |
| 92 | 134 | #+begin_src sh |