web: repo create, issue and MR create, edit and comment dispatch the command !189

merged merged by cmc on 2026-09-03 15:59 UTC · krz/gitbay:web-writes-registry into main

Discussion

cmc

Six handlers in accounts.go called the store directly, so from a browser the per-account repository quota, the archived-repository refusal, participant notifications, the stored body format and the audit entry were all skipped. They now run repo create, issue create, issue edit, mr edit, issue comment and mr comment through the registry with bodies on stdin (dispatchJSON, which also hands back the exit code so the handler maps it to an HTTP status). Labels on create and edit go through issue label, which enforces write access itself.

TestWebWritesGoThroughRegistry: with max_repos_per_user = 1, a second repository from the web is refused on the form and does not exist; an archived repository refuses a web comment.

Stacked on the runner scope MR; no code dependency between them.

Closes #93

retargeted from runner-scope to main: !188 merged

2026-09-03 15:59 UTC