auth: token contract v1 (aud windy_git, both issuers); CI for eternitas
- hub_jwt: aud list is ["windy_git"] (contract v1 array). Dropped "windy-git": that is Gitea's OIDC client_id, so a forge id_token would have passed the aud check. `type: human` is now REQUIRED (id_tokens have none), which makes accepting the discovery-URL issuer safe. - runner job ceiling 30m -> 90m: eternitas's serial pytest is ~50 min and would have been killed mid-suite. - eternitas (private) added to the GitHub status bridge. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -46,7 +46,7 @@ WG_OWNER = os.environ.get("WINDYGIT_OWNER", "windyadmin")
|
||||
REPOS = os.environ.get(
|
||||
"BRIDGE_REPOS",
|
||||
"windy-chat windy-mail windy-calendar Windy-Clone WindyCloud windy-search windy-connect"
|
||||
" windy-drops windy-code-web windy-code windy-traveler windy-registry",
|
||||
" windy-drops windy-code-web windy-code windy-traveler windy-registry eternitas",
|
||||
).split()
|
||||
|
||||
# Gitea run status -> GitHub status state. `skipped` is deliberately absent: a
|
||||
|
||||
Reference in New Issue
Block a user