feat(site): phase 1 — the foundation #4

Merged
whitlocktech merged 3 commits from feat/phase-1-foundation into main 2026-08-20 02:06:31 +00:00
3 changed files with 13 additions and 6 deletions
Showing only changes of commit b287728c19 - Show all commits

View File

@@ -44,11 +44,15 @@ jobs:
# #
# This needs a token that can read the OTHER repositories in the org: link, # This needs a token that can read the OTHER repositories in the org: link,
# servuo-plugins, website and installer. The automatic per-run token is scoped # servuo-plugins, website and installer. The automatic per-run token is scoped
# to this repository alone and will 404 on all four, so the job reads an # to this repository alone and 404s on all four, so the job uses the org-level
# org-level secret instead. # REGISTRY_TOKEN, which already exists and already carries the right scope.
#
# The secret is named for the registry; the script reads GITEA_TOKEN. Mapping it
# here rather than renaming either side keeps the script's interface honest — it
# wants a Gitea token, not this org's particular secret.
# #
# It runs last, and it is the only step that touches the network, so a Gitea # It runs last, and it is the only step that touches the network, so a Gitea
# outage cannot mask a real failure in the build. # outage cannot mask a real failure in the build.
env: env:
GITEA_TOKEN: ${{ secrets.PLATFORM_READ_TOKEN }} GITEA_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
run: npm run check:facts run: npm run check:facts

View File

@@ -56,7 +56,9 @@ on protocol 3, because every checkout in the workspace sat on a feature branch w
never been fetched. never been fetched.
It needs a token — anonymous raw fetches fail on this Gitea instance, and a check that silently skips It needs a token — anonymous raw fetches fail on this Gitea instance, and a check that silently skips
itself is worse than no check at all. itself is worse than no check at all. It must be able to read the other repositories in the
organisation, not just this one. CI already has this: the workflow maps the org-level
`REGISTRY_TOKEN` secret into `GITEA_TOKEN` for that step.
**`checkTokens.mjs`** fails the build if a colour literal appears anywhere in `src/` outside **`checkTokens.mjs`** fails the build if a colour literal appears anywhere in `src/` outside
`src/styles/tokens.css`. §7 promises that recolouring the site is a file copy and a container `src/styles/tokens.css`. §7 promises that recolouring the site is a file copy and a container

View File

@@ -231,8 +231,9 @@ async function main() {
'checkFacts: GITEA_TOKEN is not set.\n\n' + 'checkFacts: GITEA_TOKEN is not set.\n\n' +
' Anonymous raw fetches fail on this Gitea instance, and a fact check that skips\n' + ' Anonymous raw fetches fail on this Gitea instance, and a fact check that skips\n' +
' itself is worse than no fact check — a stale version would ship silently.\n\n' + ' itself is worse than no fact check — a stale version would ship silently.\n\n' +
' Locally: GITEA_TOKEN=$(grep -o "[^=]*$" ~/.gitea_token_claude) npm run check:facts\n' + ' Locally: GITEA_TOKEN=<a token that can read the org> npm run check:facts\n' +
' In CI: set GITEA_TOKEN from the repository secret.\n' ' In CI: already wired — .gitea/workflows/pr-checks.yml maps the org-level\n' +
' REGISTRY_TOKEN secret into GITEA_TOKEN for this step.\n'
); );
process.exit(2); process.exit(2);
} }