From 9b2cb6a8538746a9c55fcbda8676f0eee76db09f Mon Sep 17 00:00:00 2001 From: marcuspaico Date: Mon, 17 Aug 2026 14:45:07 -0700 Subject: [PATCH] ci: authenticated checkout via injected token Anonymous HTTPS clone fails while the repo is private; token works either way, and the internal gitea:3000 host skips the reverse proxy. Co-Authored-By: Claude Fable 5 --- .gitea/workflows/ci.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 57dfc88..d1f74fd 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -11,7 +11,9 @@ jobs: - name: Checkout run: | apt-get update -qq && apt-get install -y -qq git >/dev/null - git init -q . && git fetch -q --depth 1 "https://git.rehbock.xyz/${{ github.repository }}.git" "${{ github.sha }}" && git checkout -q FETCH_HEAD + # Token-authenticated fetch so CI works on private repos too; internal + # gitea:3000 host avoids the proxy round-trip. + git init -q . && git fetch -q --depth 1 "http://x:${{ secrets.GITHUB_TOKEN }}@gitea:3000/${{ github.repository }}.git" "${{ github.sha }}" && git checkout -q FETCH_HEAD - run: bun install --frozen-lockfile - run: bun run typecheck - run: bun run build:web