gitea: a consumer's user is actually created, and a failed create says why #71

Merged
jschoubben merged 1 commits from fix/gitea-provisioner-user-create into main 2026-09-25 19:54:08 +00:00
Owner

The builder's package-registry grant — the first this provider ever received — has been retry-looping for a day, logging only that an edit 404'd. Two faults underneath:

  1. Gitea's API refuses an email without a dotted domain, so ${as}@localhost failed validation at create. (The CLI that bootstrapped mesh-admin accepts @localhost, which is exactly why the admin exists and no consumer ever did.) The address is now @noreply.localhost — gitea's own hidden-address convention.
  2. ensureUser read the create's 422 as "already exists" and went on to PATCH a user that was never made — burying the create's own error message, the one that says what is actually wrong. The edit path is now taken only when the user actually exists; otherwise the create's failure is reported as itself.

Once merged and rolled out, the provisioner's standing retry loop should converge on its own: the user is created, the minted password applies, and mesh_novox_builder can finally authenticate — which the builder's credentialed git-clone work (in flight) depends on.

The builder's package-registry grant — the first this provider ever received — has been retry-looping for a day, logging only that an edit 404'd. Two faults underneath: 1. **Gitea's API refuses an email without a dotted domain**, so `${as}@localhost` failed validation at create. (The CLI that bootstrapped `mesh-admin` accepts `@localhost`, which is exactly why the admin exists and no consumer ever did.) The address is now `@noreply.localhost` — gitea's own hidden-address convention. 2. **`ensureUser` read the create's 422 as "already exists"** and went on to PATCH a user that was never made — burying the create's own error message, the one that says what is actually wrong. The edit path is now taken only when the user actually exists; otherwise the create's failure is reported as itself. Once merged and rolled out, the provisioner's standing retry loop should converge on its own: the user is created, the minted password applies, and `mesh_novox_builder` can finally authenticate — which the builder's credentialed git-clone work (in flight) depends on.
jschoubben added 1 commit 2026-09-25 19:42:47 +00:00
The builder's package-registry grant — the first this provider ever
received — retried for a day saying only that an edit 404'd. Two faults
under it: the API refuses an email without a dotted domain, so
`@localhost` failed validation at create (the CLI that made mesh-admin
accepts it, which is why the admin exists and no consumer did); and
ensureUser read that 422 as 'already exists' and went on to edit a user
that was never made, burying the create's own message. The address is now
gitea's own hidden-address shape, and the edit path is taken only for a
user that is actually there.
jschoubben merged commit c7964b7285 into main 2026-09-25 19:54:08 +00:00
jschoubben deleted branch fix/gitea-provisioner-user-create 2026-09-25 19:54:09 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#71