2 Commits

Author SHA1 Message Date
40cb455d0d ci: onboard windy-translate, windytranslate-site, windytraveler-site
Some checks failed
check / gate (push) Has been cancelled
Promoted to writable; the two sites' CF deploy.yml disabled (they would
need the CF god token in a job container). All three only have
ubuntu-latest workflows today, so nothing runs until their lanes switch
runs-on to [self-hosted, linux, x64].

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-23 03:13:40 -04:00
8c404eb410 security: turn off Gitea OAuth auto-registration
Any Windy Word account (public signup, unverified email) auto-registered a
forge account on first sign-in — reproduced with a throwaway account —
and the act runners are instance-wide, so a stranger's workflow would run
on Veron's privileged dind beside the R2 god token. §7 makes opening the
forge to non-Grant users Grant's call.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-23 03:09:43 -04:00
3 changed files with 10 additions and 3 deletions

View File

@@ -66,7 +66,13 @@ services:
# G3.1 — a Windy account IS the account. Signing in with Windy provisions
# the Gitea user on first arrival; nobody is asked to invent a second
# identity for the same person, and no local password ever exists.
GITEA__oauth2_client__ENABLE_AUTO_REGISTRATION: "true"
# 🔴 OFF (2026-09-23). With it on, ANY stranger with a Windy Word account
# (public signup, not even email-verified) got a forge account on first
# sign-in — and the CI runners were instance-wide, so their workflows
# would run on Veron beside the R2 god token. Proven with a throwaway
# account, then closed. Opening the forge to non-Grant users is a §7
# Grant decision; until then new accounts are created deliberately.
GITEA__oauth2_client__ENABLE_AUTO_REGISTRATION: "false"
GITEA__oauth2_client__USERNAME: email
# 🔴 `login`, NOT `auto` (SSO #8). `auto` linked any hub login whose EMAIL
# matched an existing account — and windyadmin (SITE ADMIN) carries Grant's

View File

@@ -46,7 +46,8 @@ WG_OWNER = os.environ.get("WINDYGIT_OWNER", "windyadmin")
REPOS = os.environ.get(
"BRIDGE_REPOS",
"windy-chat windy-mail windy-calendar Windy-Clone WindyCloud windy-search windy-connect"
" windy-drops windy-code-web windy-code windy-traveler windy-registry eternitas",
" windy-drops windy-code-web windy-code windy-traveler windy-registry eternitas"
" windy-translate windytranslate-site windytraveler-site",
).split()
# Gitea run status -> GitHub status state. `skipped` is deliberately absent: a

View File

@@ -38,7 +38,7 @@ FAILED=0
# Repos Windy Git tracks FROM GitHub. Remove a repo from this list at the moment
# it flips to Windy-Git-first, or the sync will fight its authors and win.
REPOS="${SYNC_REPOS:-windy-calendar windy-search windy-registry Windy-Clone WindyCloud windy-cloud-sites windy-mind eternitas windy-agent windy-git windy-chat windy-mail windy-connect windy-drops windy-code-web windy-code windy-traveler}"
REPOS="${SYNC_REPOS:-windy-calendar windy-search windy-registry Windy-Clone WindyCloud windy-cloud-sites windy-mind eternitas windy-agent windy-git windy-chat windy-mail windy-connect windy-drops windy-code-web windy-code windy-traveler windy-translate windytranslate-site windytraveler-site}"
mkdir -p "$WORK"
log() { printf '[sync %s] %s\n' "$(date -u +%H:%M:%SZ)" "$*"; }