diff --git a/.claude-plugin/plugin.json b/.claude-plugin/plugin.json index 4a302c8..4732f37 100644 --- a/.claude-plugin/plugin.json +++ b/.claude-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "jsc-gitea", - "version": "0.0.8", + "version": "0.0.9", "description": "Gitea API 工具、Wiki 讀寫與存取庫批次同步", "skills": "./skills", "author": { diff --git a/.codex-plugin/plugin.json b/.codex-plugin/plugin.json index e04331f..46895bd 100644 --- a/.codex-plugin/plugin.json +++ b/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "jsc-gitea", - "version": "0.0.8", + "version": "0.0.9", "description": "Gitea API 工具、Wiki 讀寫與存取庫批次同步", "skills": "./skills" } diff --git a/plugin.json b/plugin.json index 663cfe1..b6739f4 100644 --- a/plugin.json +++ b/plugin.json @@ -1,6 +1,6 @@ { "name": "jsc-gitea", - "version": "0.0.8", + "version": "0.0.9", "description": "Gitea API 工具、Wiki 讀寫與存取庫批次同步", "skills": "./skills/" } diff --git a/tools/gitea.sh b/tools/gitea.sh index cb0e8eb..3502852 100755 --- a/tools/gitea.sh +++ b/tools/gitea.sh @@ -46,22 +46,45 @@ case "$cmd" in exit 0 ;; esac -tea_token() { # 取 tea CLI 設定檔的 token(優先 default: true 的登入,否則第一個) +tea_token() { # 取 tea CLI 設定檔的 token。$1=host-only 時,只回傳主機相符的登入 + # 優先序:url 與 $GITEA_HOST 同主機的登入 > default: true 的登入 > 第一個登入。 + # 主機比對必須排最前面:tea 可以同時登入多個站台,只看 default 會把 A 站的 + # token 送去 B 站——那是憑證外洩,不是單純的取錯值。 cfg="${HOME}/.config/tea/config.yml" [ -f "$cfg" ] || return 1 - t=$(awk ' - /^ *- / { if (def && tok != "") { print tok; found=1; exit } tok=""; def=0 } - /^ *token: */ { line=$0; sub(/^ *token: */,"",line); gsub(/"/,"",line) - tok=line; if (first=="") first=line } + only_host="${1:-}" + want=$(printf '%s' "${GITEA_HOST:-}" | sed 's#^https\{0,1\}://##; s#/.*##') + t=$(awk -v want="$want" -v only_host="$only_host" ' + function flush() { + if (tok == "") return + if (first == "") first = tok + if (want != "" && host == want) { match_tok = tok } + if (def) def_tok = tok + } + /^ *- / { flush(); tok=""; host=""; def=0 } + /^ *token: */ { line=$0; sub(/^ *token: */,"",line); gsub(/"/,"",line); tok=line } + /^ *url: */ { line=$0; sub(/^ *url: */,"",line); gsub(/"/,"",line) + sub(/^https?:\/\//,"",line); sub(/\/.*$/,"",line); host=line } /^ *default: *true/ { def=1 } - END { if (!found) { if (def && tok != "") print tok; else print first } } + END { + flush() + if (match_tok != "") { print match_tok; exit } + if (only_host == "host-only") exit + if (def_tok != "") print def_tok + else print first + } ' "$cfg") [ -n "$t" ] && printf '%s\n' "$t" } : "${GITEA_HOST:?GITEA_HOST is required}" TEA_TOKEN=$(tea_token 2>/dev/null || true) -if [ -z "${GITEA_TOKEN:-}" ]; then +TEA_HOST_TOKEN=$(tea_token host-only 2>/dev/null || true) +if [ -n "$TEA_HOST_TOKEN" ]; then + # tea 有這個主機的專用登入就優先用它。$GITEA_TOKEN 是通用變數,未必屬於 + # 這次要連的主機;把它送去別的站等於憑證外洩,比取錯值嚴重得多。 + GITEA_TOKEN="$TEA_HOST_TOKEN" +elif [ -z "${GITEA_TOKEN:-}" ]; then if [ -n "$TEA_TOKEN" ]; then GITEA_TOKEN="$TEA_TOKEN"; else : "${GITEA_TOKEN:?GITEA_TOKEN is required}" fi