ci(facts): use the existing org-level REGISTRY_TOKEN
All checks were successful
PR checks / checks (pull_request) Successful in 9m11s

checkFacts needs to read link, servuo-plugins, website and installer, and
the automatic per-run token is scoped to this repo alone. Rather than mint
a new secret, the workflow uses REGISTRY_TOKEN, which already exists at the
org level with the right permissions.

The secret is named for the registry and the script reads GITEA_TOKEN; the
mapping stays in the workflow so the script keeps asking for what it
actually wants -- a Gitea token -- rather than this org's secret name.

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
2026-08-19 20:46:18 -05:00
parent d4ab453361
commit b287728c19
3 changed files with 13 additions and 6 deletions

View File

@@ -44,11 +44,15 @@ jobs:
# #
# This needs a token that can read the OTHER repositories in the org: link, # This needs a token that can read the OTHER repositories in the org: link,
# servuo-plugins, website and installer. The automatic per-run token is scoped # servuo-plugins, website and installer. The automatic per-run token is scoped
# to this repository alone and will 404 on all four, so the job reads an # to this repository alone and 404s on all four, so the job uses the org-level
# org-level secret instead. # REGISTRY_TOKEN, which already exists and already carries the right scope.
#
# The secret is named for the registry; the script reads GITEA_TOKEN. Mapping it
# here rather than renaming either side keeps the script's interface honest — it
# wants a Gitea token, not this org's particular secret.
# #
# It runs last, and it is the only step that touches the network, so a Gitea # It runs last, and it is the only step that touches the network, so a Gitea
# outage cannot mask a real failure in the build. # outage cannot mask a real failure in the build.
env: env:
GITEA_TOKEN: ${{ secrets.PLATFORM_READ_TOKEN }} GITEA_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
run: npm run check:facts run: npm run check:facts

View File

@@ -56,7 +56,9 @@ on protocol 3, because every checkout in the workspace sat on a feature branch w
never been fetched. never been fetched.
It needs a token — anonymous raw fetches fail on this Gitea instance, and a check that silently skips It needs a token — anonymous raw fetches fail on this Gitea instance, and a check that silently skips
itself is worse than no check at all. itself is worse than no check at all. It must be able to read the other repositories in the
organisation, not just this one. CI already has this: the workflow maps the org-level
`REGISTRY_TOKEN` secret into `GITEA_TOKEN` for that step.
**`checkTokens.mjs`** fails the build if a colour literal appears anywhere in `src/` outside **`checkTokens.mjs`** fails the build if a colour literal appears anywhere in `src/` outside
`src/styles/tokens.css`. §7 promises that recolouring the site is a file copy and a container `src/styles/tokens.css`. §7 promises that recolouring the site is a file copy and a container

View File

@@ -231,8 +231,9 @@ async function main() {
'checkFacts: GITEA_TOKEN is not set.\n\n' + 'checkFacts: GITEA_TOKEN is not set.\n\n' +
' Anonymous raw fetches fail on this Gitea instance, and a fact check that skips\n' + ' Anonymous raw fetches fail on this Gitea instance, and a fact check that skips\n' +
' itself is worse than no fact check — a stale version would ship silently.\n\n' + ' itself is worse than no fact check — a stale version would ship silently.\n\n' +
' Locally: GITEA_TOKEN=$(grep -o "[^=]*$" ~/.gitea_token_claude) npm run check:facts\n' + ' Locally: GITEA_TOKEN=<a token that can read the org> npm run check:facts\n' +
' In CI: set GITEA_TOKEN from the repository secret.\n' ' In CI: already wired — .gitea/workflows/pr-checks.yml maps the org-level\n' +
' REGISTRY_TOKEN secret into GITEA_TOKEN for this step.\n'
); );
process.exit(2); process.exit(2);
} }