security: turn off Gitea OAuth auto-registration

Any Windy Word account (public signup, unverified email) auto-registered a
forge account on first sign-in — reproduced with a throwaway account —
and the act runners are instance-wide, so a stranger's workflow would run
on Veron's privileged dind beside the R2 god token. §7 makes opening the
forge to non-Grant users Grant's call.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-23 03:09:43 -04:00
parent 5b16114b98
commit 8c404eb410

View File

@@ -66,7 +66,13 @@ services:
# G3.1 — a Windy account IS the account. Signing in with Windy provisions # G3.1 — a Windy account IS the account. Signing in with Windy provisions
# the Gitea user on first arrival; nobody is asked to invent a second # the Gitea user on first arrival; nobody is asked to invent a second
# identity for the same person, and no local password ever exists. # identity for the same person, and no local password ever exists.
GITEA__oauth2_client__ENABLE_AUTO_REGISTRATION: "true" # 🔴 OFF (2026-09-23). With it on, ANY stranger with a Windy Word account
# (public signup, not even email-verified) got a forge account on first
# sign-in — and the CI runners were instance-wide, so their workflows
# would run on Veron beside the R2 god token. Proven with a throwaway
# account, then closed. Opening the forge to non-Grant users is a §7
# Grant decision; until then new accounts are created deliberately.
GITEA__oauth2_client__ENABLE_AUTO_REGISTRATION: "false"
GITEA__oauth2_client__USERNAME: email GITEA__oauth2_client__USERNAME: email
# 🔴 `login`, NOT `auto` (SSO #8). `auto` linked any hub login whose EMAIL # 🔴 `login`, NOT `auto` (SSO #8). `auto` linked any hub login whose EMAIL
# matched an existing account — and windyadmin (SITE ADMIN) carries Grant's # matched an existing account — and windyadmin (SITE ADMIN) carries Grant's