From c2353fc0a635235d1ae1aeba9cea195715ce9d69 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 25 Sep 2026 20:51:44 +0200 Subject: [PATCH] gitea: the internal-API refusal is part of the route, not a file beside the proxy The 2026-09-12 incident response blocked /api/internal by hand in the predecessor's dynamic directory, with a note that its durable home is the mesh's routing. A route carries the policy applied to a request (ADR 0108), so the refusal now travels with the grant: route-proxy enforces it on both the public name and the internal alias the moment it serves this route, and the adapter skips it aloud (no port, nothing to write) while the predecessor's own file still stands. The hand-authored file retires with the proxy it configures. --- modules/gitea/module.json | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/modules/gitea/module.json b/modules/gitea/module.json index a6ef32f..3b1b705 100644 --- a/modules/gitea/module.json +++ b/modules/gitea/module.json @@ -11,8 +11,16 @@ "name": "gitea" }, "route": { - "label": "git", - "port": 3000 + "web": { + "label": "git", + "port": 3000 + }, + "internal-api-refused": { + "label": "git", + "path": "/api/internal", + "deny": true, + "priority": 100000 + } } }, "binds": {