Web UI: Updated tab, inline errors, mobile card fixes #3
@@ -87,6 +87,17 @@ Local stack: `docker compose up` (named volume mounted at `/data`, `restart: unl
|
|||||||
|
|
||||||
Smoke test: `curl` the endpoints with `Authorization: Bearer <token>`; confirm `OPTIONS` preflight returns CORS headers and `/healthz` returns 200.
|
Smoke test: `curl` the endpoints with `Authorization: Bearer <token>`; confirm `OPTIONS` preflight returns CORS headers and `/healthz` returns 200.
|
||||||
|
|
||||||
|
## Forge: Gitea, not GitHub
|
||||||
|
|
||||||
|
`origin` is a self-hosted Gitea instance (`gitea.violetcrown.my.id`), so **`gh` does not work here — use `tea` (Gitea CLI) for anything past plain git.** Common ones:
|
||||||
|
|
||||||
|
- Open a PR: `tea pr create --head <branch> --base main --title "..." --description "..."`
|
||||||
|
- List / view / check out: `tea pr list`, `tea pr <n>`, `tea pr checkout <n>`
|
||||||
|
- Issues: `tea issue create`, `tea issue list`
|
||||||
|
- Auth lives in `tea login`, not a `GH_TOKEN` env var.
|
||||||
|
|
||||||
|
`tea` prints its output as rendered boxes rather than plain text; the PR URL lands on the last line.
|
||||||
|
|
||||||
## Security invariants
|
## Security invariants
|
||||||
|
|
||||||
- Auth on `/bookmarks*`: require `Authorization: Bearer <API_TOKEN>`, **constant-time compare**, 401 otherwise.
|
- Auth on `/bookmarks*`: require `Authorization: Bearer <API_TOKEN>`, **constant-time compare**, 401 otherwise.
|
||||||
|
|||||||
Reference in New Issue
Block a user