From 8c404eb41071a405d697c520b4a801a42c2ceb13 Mon Sep 17 00:00:00 2001 From: Grant Whitmer Date: Wed, 23 Sep 2026 03:09:43 -0400 Subject: [PATCH] security: turn off Gitea OAuth auto-registration MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Any Windy Word account (public signup, unverified email) auto-registered a forge account on first sign-in โ€” reproduced with a throwaway account โ€” and the act runners are instance-wide, so a stranger's workflow would run on Veron's privileged dind beside the R2 god token. ยง7 makes opening the forge to non-Grant users Grant's call. Co-Authored-By: Claude Opus 5.5 --- docker-compose.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/docker-compose.yml b/docker-compose.yml index 89dd6d4..3db8c4e 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -66,7 +66,13 @@ services: # G3.1 โ€” a Windy account IS the account. Signing in with Windy provisions # the Gitea user on first arrival; nobody is asked to invent a second # identity for the same person, and no local password ever exists. - GITEA__oauth2_client__ENABLE_AUTO_REGISTRATION: "true" + # ๐Ÿ”ด OFF (2026-09-23). With it on, ANY stranger with a Windy Word account + # (public signup, not even email-verified) got a forge account on first + # sign-in โ€” and the CI runners were instance-wide, so their workflows + # would run on Veron beside the R2 god token. Proven with a throwaway + # account, then closed. Opening the forge to non-Grant users is a ยง7 + # Grant decision; until then new accounts are created deliberately. + GITEA__oauth2_client__ENABLE_AUTO_REGISTRATION: "false" GITEA__oauth2_client__USERNAME: email # ๐Ÿ”ด `login`, NOT `auto` (SSO #8). `auto` linked any hub login whose EMAIL # matched an existing account โ€” and windyadmin (SITE ADMIN) carries Grant's