gitea: a consumer's user is actually created, and a failed create says why #71
+15
-8
@@ -387,7 +387,11 @@ export class GiteaAdmin {
|
|||||||
}
|
}
|
||||||
|
|
||||||
/** Ensure a user exists with exactly this password. Created if absent; if already there, its
|
/** Ensure a user exists with exactly this password. Created if absent; if already there, its
|
||||||
* password is patched — so the mesh minting a new secret takes on the next reconcile. */
|
* password is patched — so the mesh minting a new secret takes on the next reconcile.
|
||||||
|
*
|
||||||
|
* The edit path is taken only when the user actually exists. A 422 from the create is also what
|
||||||
|
* a plain validation failure returns, and reading it as "already there" made the follow-up edit
|
||||||
|
* 404 — burying the create's own message, which is the one that says what is actually wrong. */
|
||||||
async ensureUser(username: string, password: string, email: string): Promise<void> {
|
async ensureUser(username: string, password: string, email: string): Promise<void> {
|
||||||
const res = await this.request("/admin/users", {
|
const res = await this.request("/admin/users", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
@@ -395,13 +399,16 @@ export class GiteaAdmin {
|
|||||||
});
|
});
|
||||||
if (res.status === 201) return;
|
if (res.status === 201) return;
|
||||||
if (res.status === 422 || res.status === 409) {
|
if (res.status === 422 || res.status === 409) {
|
||||||
const patch = await this.request(`/admin/users/${encodeURIComponent(username)}`, {
|
const seen = await this.request(`/users/${encodeURIComponent(username)}`);
|
||||||
method: "PATCH",
|
if (seen.status === 200) {
|
||||||
// login_name is required by the admin edit endpoint; for a local user it is the username.
|
const patch = await this.request(`/admin/users/${encodeURIComponent(username)}`, {
|
||||||
body: JSON.stringify({ login_name: username, password, must_change_password: false }),
|
method: "PATCH",
|
||||||
});
|
// login_name is required by the admin edit endpoint; for a local user it is the username.
|
||||||
if (patch.status === 200) return;
|
body: JSON.stringify({ login_name: username, password, must_change_password: false }),
|
||||||
GiteaAdmin.fail(`/admin/users/${username}`, patch);
|
});
|
||||||
|
if (patch.status === 200) return;
|
||||||
|
GiteaAdmin.fail(`/admin/users/${username}`, patch);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
GiteaAdmin.fail("/admin/users", res);
|
GiteaAdmin.fail("/admin/users", res);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -34,7 +34,12 @@ runProvisioner("package-registry", {
|
|||||||
const teamId = await gitea.ensureTeam(ORG, PACKAGE_TEAM, true);
|
const teamId = await gitea.ensureTeam(ORG, PACKAGE_TEAM, true);
|
||||||
// The user carries the consumer's login and the mesh's minted password, set every run so a
|
// The user carries the consumer's login and the mesh's minted password, set every run so a
|
||||||
// rotation takes. Membership of the package team is what grants read+write on packages.
|
// rotation takes. Membership of the package team is what grants read+write on packages.
|
||||||
await gitea.ensureUser(p.as, p.password, `${p.as}@localhost`);
|
//
|
||||||
|
// The address is gitea's own convention for one that is not real: its email validation
|
||||||
|
// requires a dotted domain, so `@localhost` was refused at create — the fault that had this
|
||||||
|
// grant retrying for a day — while `@noreply.localhost` is the shape gitea itself gives
|
||||||
|
// hidden addresses.
|
||||||
|
await gitea.ensureUser(p.as, p.password, `${p.as}@noreply.localhost`);
|
||||||
await gitea.addUserToTeam(teamId, p.as);
|
await gitea.addUserToTeam(teamId, p.as);
|
||||||
},
|
},
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user