gitea: the token needs read:user, not just write:repository and write:issue #51

Merged
jschoubben merged 1 commits from fix/gitea-user-repos-scope into main 2026-09-24 09:49:37 +00:00
1 Commits
Author SHA1 Message Date
jschoubben aaf341a2d8 gitea: the token needs read:user, not just write:repository and write:issue
Deployed #49 and the watcher immediately broke: GET /user/repos answered 403,
'required=[read:user]' — confirmed live against the running forge (1.27.3).
That route sits under gitea's user scope category despite listing
repositories, not repository as assumed.

Also gives the fake forge real scope enforcement on /user/repos, which is
why the original PR's test suite didn't catch this: it only checked the
token's value was valid, never that it carried the required scope.
2026-09-24 11:43:46 +02:00