ReadOnly decides four things at once: read-scoped tokens may run the command, GET /api/v1/read reaches it, it draws on the read rate budget, and it is not audited. Nothing checked that a command flagged ReadOnly only reads.
TestReadOnlyCommandsWriteNothing builds an instance with a repository, history, a tag, an MR with a diff thread, an issue with a label and milestone, a release with an asset, a queued build, an org with a team, a token, a browser session, a deploy key, a secret and a webhook, then runs all 62 ReadOnly commands from the registry as an admin and hashes every table between runs, naming the command and table on any change. A ReadOnly command with no arguments in the test fails it, so a new read command has to be added here.
Two exemptions, both stated in the test: commit_signatures, the signature-verification cache that whichever read first shows a commit fills (a memo, not state), and the last_used_at/last_seen columns an ssh session touches by design. All 62 commands currently pass.
Stacked on !196; no code dependency.
Closes #97
retargeted from admin-gate to main: !196 merged
2026-09-03 18:47 UTC