hq #229: the mesh's gitea tools (ask gitea gitea_api) could not make the builder's login a site admin — 403 required=[write:admin], the token was minted with write:repository, write:issue, read:user only. This adds write:admin to TOKEN_SCOPES, and makes the client treat the forge's 403 token does not have at least one of required scope(s) like a 401: the source re-mints by name with the whole list and retries once, so a kept token from a previous build heals on first use. Any other 403 stays the forge's answer.
The token tests were stale on main: the client lists through /repos/search since 2026-09-28 and the fake forge only knew /user/repos, so 9 of 11 failed. The fake learns the search route; 12/12 pass now (run locally with the module's deps from gitea's npm registry).
Rollout: rebuild gitea, push novox — the sidecar restarts, reuses the kept token, and re-mints it the first time an admin call answers 403.
hq #229: the mesh's gitea tools (`ask gitea gitea_api`) could not make the builder's login a site admin — `403 required=[write:admin]`, the token was minted with `write:repository, write:issue, read:user` only. This adds `write:admin` to `TOKEN_SCOPES`, and makes the client treat the forge's `403 token does not have at least one of required scope(s)` like a 401: the source re-mints by name with the whole list and retries once, so a kept token from a previous build heals on first use. Any other 403 stays the forge's answer.
The token tests were stale on main: the client lists through `/repos/search` since 2026-09-28 and the fake forge only knew `/user/repos`, so 9 of 11 failed. The fake learns the search route; 12/12 pass now (run locally with the module's deps from gitea's npm registry).
Rollout: rebuild gitea, push novox — the sidecar restarts, reuses the kept token, and re-mints it the first time an admin call answers 403.
The forge's own users are the mesh's to settle — making the builder's login
a site admin so private repos build (hq 229) — and the tools' token had no
write:admin. A token kept from before a scope was added lacks it, so the
client now treats the forge's 403 "required scope" like a 401: the source
re-mints by name with the whole list and retries once. The fake forge in the
tests learns /repos/search, which the client has used since 2026-09-28 and
which had left 9 of the 11 token tests failing on main.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
hq #229: the mesh's gitea tools (
ask gitea gitea_api) could not make the builder's login a site admin —403 required=[write:admin], the token was minted withwrite:repository, write:issue, read:useronly. This addswrite:admintoTOKEN_SCOPES, and makes the client treat the forge's403 token does not have at least one of required scope(s)like a 401: the source re-mints by name with the whole list and retries once, so a kept token from a previous build heals on first use. Any other 403 stays the forge's answer.The token tests were stale on main: the client lists through
/repos/searchsince 2026-09-28 and the fake forge only knew/user/repos, so 9 of 11 failed. The fake learns the search route; 12/12 pass now (run locally with the module's deps from gitea's npm registry).Rollout: rebuild gitea, push novox — the sidecar restarts, reuses the kept token, and re-mints it the first time an admin call answers 403.