From 0c669122ea713621592b6d81a96b68e183d935e6 Mon Sep 17 00:00:00 2001 From: Matthew Daubney Date: Sun, 27 Sep 2026 23:36:36 +0100 Subject: [PATCH] Use a dedicated PAT for Gitea package registry uploads The automatic Actions token (GITEA_TOKEN) returns 401 against the packages content API in this Gitea version, and GITEA_/GITHUB_- prefixed names are reserved for secrets anyway. Switch to a dedicated write:package-scoped token stored as PKG_REGISTRY_TOKEN. Co-Authored-By: Claude Sonnet 5 Claude-Session: https://claude.ai/code/session_018n5ffHCn5QUjpDtuWTk3fh --- .gitea/workflows/ci.yml | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 5db5202..f23f085 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -90,26 +90,26 @@ jobs: done - name: Upload plugin artifact to Gitea package registry env: - GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} + PKG_REGISTRY_TOKEN: ${{ secrets.PKG_REGISTRY_TOKEN }} BASE: ${{ github.server_url }}/api/packages/${{ github.repository_owner }}/generic/${{ env.PLUGIN_ID }} run: | if [[ "$GITHUB_REF" == refs/tags/v* ]]; then dirs="${GITHUB_REF_NAME#v}"; else dirs="main sha-${GITHUB_SHA::7}"; fi # Generic packages are immutable per version: delete first (ignored if absent) so # a re-run or a repeated push to a mutable version like "main" doesn't 409. for dir in $dirs; do - curl -fsS -X DELETE -H "Authorization: token $GITEA_TOKEN" "$BASE/$dir" || true - curl -fsS -X PUT -H "Authorization: token $GITEA_TOKEN" \ + curl -fsS -X DELETE -H "Authorization: token $PKG_REGISTRY_TOKEN" "$BASE/$dir" || true + curl -fsS -X PUT -H "Authorization: token $PKG_REGISTRY_TOKEN" \ --upload-file "dist/${PLUGIN_ID}.ndp" "$BASE/$dir/${PLUGIN_ID}.ndp" - curl -fsS -X PUT -H "Authorization: token $GITEA_TOKEN" \ + curl -fsS -X PUT -H "Authorization: token $PKG_REGISTRY_TOKEN" \ --upload-file "manifest.json" "$BASE/$dir/manifest.json" echo "uploaded $dir/${PLUGIN_ID}.ndp to Gitea packages" done - name: Link Gitea package to this repo env: - GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} + PKG_REGISTRY_TOKEN: ${{ secrets.PKG_REGISTRY_TOKEN }} run: | repo_name="${GITHUB_REPOSITORY#*/}" - curl -fsS -X POST -H "Authorization: token $GITEA_TOKEN" \ + curl -fsS -X POST -H "Authorization: token $PKG_REGISTRY_TOKEN" \ "${{ github.server_url }}/api/v1/packages/${{ github.repository_owner }}/generic/${{ env.PLUGIN_ID }}/-/link/$repo_name" \ || echo "link skipped (already linked, or not yet supported)"