Commit bd1b95ee5d
Verified · cmc
Layout: unified · split
Admin.org +5
| @@ -210,6 +210,11 @@ owners that exist). The domain must not be the site host or a parent of | |||
| 210 | it — pages content runs its own scripts and must stay off the forge's | 210 | it — pages content runs its own scripts and must stay off the forge's |
| 211 | origin. | 211 | origin. |
| 212 | 212 | ||
| 213 | Users with repo admin claim custom domains with =repo domain add=; ACME | ||
| 214 | issues certificates only for claimed hosts, so stray DNS pointed at the | ||
| 215 | server gets nothing. Claims are unverified in v1 — fine while | ||
| 216 | registration is closed; add DNS TXT verification before opening it. | ||
| 217 | |||
| 213 | * Security | 218 | * Security |
| 214 | 219 | ||
| 215 | The [[Threat-Model]] file is the reference for what the forge | 220 | The [[Threat-Model]] file is the reference for what the forge |
Users.org +7
| @@ -329,6 +329,13 @@ build and push the branch for automatic deploys. Sites run on a | |||
| 329 | separate origin — your scripts work, and the forge's cookies are out of | 329 | separate origin — your scripts work, and the forge's cookies are out of |
| 330 | reach. | 330 | reach. |
| 331 | 331 | ||
| 332 | A repo can also serve its pages branch on a domain you own: | ||
| 333 | =gitbay repo domain add <owner/name> <domain>=, then point the domain's | ||
| 334 | A/AAAA records at the instance (DNS-only if the domain sits behind a | ||
| 335 | proxying provider — the instance issues its own certificates). Claims | ||
| 336 | are exclusive per instance; =repo domain list= and =repo show= report | ||
| 337 | them. | ||
| 338 | |||
| 332 | * Notifications | 339 | * Notifications |
| 333 | 340 | ||
| 334 | When the instance has SMTP configured, activity mails you: someone | 341 | When the instance has SMTP configured, activity mails you: someone |