Compare commits
2 Commits
5b16114b98
...
40cb455d0d
| Author | SHA1 | Date | |
|---|---|---|---|
| 40cb455d0d | |||
| 8c404eb410 |
@@ -66,7 +66,13 @@ services:
|
|||||||
# G3.1 — a Windy account IS the account. Signing in with Windy provisions
|
# G3.1 — a Windy account IS the account. Signing in with Windy provisions
|
||||||
# the Gitea user on first arrival; nobody is asked to invent a second
|
# the Gitea user on first arrival; nobody is asked to invent a second
|
||||||
# identity for the same person, and no local password ever exists.
|
# identity for the same person, and no local password ever exists.
|
||||||
GITEA__oauth2_client__ENABLE_AUTO_REGISTRATION: "true"
|
# 🔴 OFF (2026-09-23). With it on, ANY stranger with a Windy Word account
|
||||||
|
# (public signup, not even email-verified) got a forge account on first
|
||||||
|
# sign-in — and the CI runners were instance-wide, so their workflows
|
||||||
|
# would run on Veron beside the R2 god token. Proven with a throwaway
|
||||||
|
# account, then closed. Opening the forge to non-Grant users is a §7
|
||||||
|
# Grant decision; until then new accounts are created deliberately.
|
||||||
|
GITEA__oauth2_client__ENABLE_AUTO_REGISTRATION: "false"
|
||||||
GITEA__oauth2_client__USERNAME: email
|
GITEA__oauth2_client__USERNAME: email
|
||||||
# 🔴 `login`, NOT `auto` (SSO #8). `auto` linked any hub login whose EMAIL
|
# 🔴 `login`, NOT `auto` (SSO #8). `auto` linked any hub login whose EMAIL
|
||||||
# matched an existing account — and windyadmin (SITE ADMIN) carries Grant's
|
# matched an existing account — and windyadmin (SITE ADMIN) carries Grant's
|
||||||
|
|||||||
@@ -46,7 +46,8 @@ WG_OWNER = os.environ.get("WINDYGIT_OWNER", "windyadmin")
|
|||||||
REPOS = os.environ.get(
|
REPOS = os.environ.get(
|
||||||
"BRIDGE_REPOS",
|
"BRIDGE_REPOS",
|
||||||
"windy-chat windy-mail windy-calendar Windy-Clone WindyCloud windy-search windy-connect"
|
"windy-chat windy-mail windy-calendar Windy-Clone WindyCloud windy-search windy-connect"
|
||||||
" windy-drops windy-code-web windy-code windy-traveler windy-registry eternitas",
|
" windy-drops windy-code-web windy-code windy-traveler windy-registry eternitas"
|
||||||
|
" windy-translate windytranslate-site windytraveler-site",
|
||||||
).split()
|
).split()
|
||||||
|
|
||||||
# Gitea run status -> GitHub status state. `skipped` is deliberately absent: a
|
# Gitea run status -> GitHub status state. `skipped` is deliberately absent: a
|
||||||
|
|||||||
@@ -38,7 +38,7 @@ FAILED=0
|
|||||||
|
|
||||||
# Repos Windy Git tracks FROM GitHub. Remove a repo from this list at the moment
|
# Repos Windy Git tracks FROM GitHub. Remove a repo from this list at the moment
|
||||||
# it flips to Windy-Git-first, or the sync will fight its authors and win.
|
# it flips to Windy-Git-first, or the sync will fight its authors and win.
|
||||||
REPOS="${SYNC_REPOS:-windy-calendar windy-search windy-registry Windy-Clone WindyCloud windy-cloud-sites windy-mind eternitas windy-agent windy-git windy-chat windy-mail windy-connect windy-drops windy-code-web windy-code windy-traveler}"
|
REPOS="${SYNC_REPOS:-windy-calendar windy-search windy-registry Windy-Clone WindyCloud windy-cloud-sites windy-mind eternitas windy-agent windy-git windy-chat windy-mail windy-connect windy-drops windy-code-web windy-code windy-traveler windy-translate windytranslate-site windytraveler-site}"
|
||||||
|
|
||||||
mkdir -p "$WORK"
|
mkdir -p "$WORK"
|
||||||
log() { printf '[sync %s] %s\n' "$(date -u +%H:%M:%SZ)" "$*"; }
|
log() { printf '[sync %s] %s\n' "$(date -u +%H:%M:%SZ)" "$*"; }
|
||||||
|
|||||||
Reference in New Issue
Block a user