feat(gitea): gitea.sh 認證失敗時自動退回 tea CLI 登入 token

What(改了什麼)
- tools/gitea.sh 新增 tea_token():解析 ~/.config/tea/config.yml,優先取 default: true 的登入 token,否則取第一個。
- 啟動時 GITEA_TOKEN 未設定或為空,改用 tea token;兩者皆無才維持原本的必填錯誤。
- req() 遇 HTTP 401/403 且 tea token 存在又與當前 token 不同時,換用 tea token 重試一次,之後不再重試。
- 檔頭用法註解補上退回機制的說明。

Why(為什麼改)
- 使用者規則:api token 401/403 時,若 tea CLI 已登入就取其 token 重試,避免因 GITEA_TOKEN 過期或未設定就直接中斷流程。

How(怎麼改)
- 以 awk 解析 tea 設定檔的 logins 清單,抓各登入的 token 與 default 旗標。
- req() 改為 while 迴圈包住 curl,retried 旗標保證最多重試一次;HTTP >= 400 仍以 exit 4 收場。
- 實測:sh -n 語法檢查通過;GITEA_TOKEN 為空時經 tea token 成功;GITEA_TOKEN=deadbeef 時走 401 重試路徑成功;無 tea 設定且 token 為空時維持原錯誤訊息。

Who(影響哪個功能/使用者)
- 所有經 tools/gitea.sh 呼叫 Gitea API 的技能(wiki、repo-sync、jsc-git pr 等)與使用者:token 缺失或失效時多一層自動救援,行為只在原本會失敗的情境改變。

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-21 08:23:27 +00:00
co-authored by Claude Fable 5
parent 050ad20cd5
commit 684d3f4f31
+30 -2
View File
@@ -17,15 +17,37 @@
# gitea.sh repo-set <owner>/<repo> <description> [website] # 設定 repo 描述與網頁 # gitea.sh repo-set <owner>/<repo> <description> [website] # 設定 repo 描述與網頁
# gitea.sh api <METHOD> <path> [json-file] # 原始 API 呼叫(path 以 /repos/... 起始) # gitea.sh api <METHOD> <path> [json-file] # 原始 API 呼叫(path 以 /repos/... 起始)
# 環境變數: GITEA_HOST(例 https://gitea.jsc.idv.tw)、GITEA_TOKEN # 環境變數: GITEA_HOST(例 https://gitea.jsc.idv.tw)、GITEA_TOKEN
# GITEA_TOKEN 未設定,或請求遇 401/403 時,自動退回 tea CLI 的登入 token
# (~/.config/tea/config.yml,優先取 default: true 的登入);兩者皆無才失敗。
set -eu set -eu
tea_token() { # 取 tea CLI 設定檔的 token(優先 default: true 的登入,否則第一個)
cfg="${HOME}/.config/tea/config.yml"
[ -f "$cfg" ] || return 1
t=$(awk '
/^ *- / { if (def && tok != "") { print tok; found=1; exit } tok=""; def=0 }
/^ *token: */ { line=$0; sub(/^ *token: */,"",line); gsub(/"/,"",line)
tok=line; if (first=="") first=line }
/^ *default: *true/ { def=1 }
END { if (!found) { if (def && tok != "") print tok; else print first } }
' "$cfg")
[ -n "$t" ] && printf '%s\n' "$t"
}
: "${GITEA_HOST:?GITEA_HOST is required}" : "${GITEA_HOST:?GITEA_HOST is required}"
: "${GITEA_TOKEN:?GITEA_TOKEN is required}" TEA_TOKEN=$(tea_token 2>/dev/null || true)
if [ -z "${GITEA_TOKEN:-}" ]; then
if [ -n "$TEA_TOKEN" ]; then GITEA_TOKEN="$TEA_TOKEN"; else
: "${GITEA_TOKEN:?GITEA_TOKEN is required}"
fi
fi
case "$GITEA_HOST" in http://*|https://*) HOST="$GITEA_HOST" ;; *) HOST="https://$GITEA_HOST" ;; esac case "$GITEA_HOST" in http://*|https://*) HOST="$GITEA_HOST" ;; *) HOST="https://$GITEA_HOST" ;; esac
API="${HOST%/}/api/v1" API="${HOST%/}/api/v1"
req() { # METHOD path [json-file] -> body(HTTP >= 400 時 exit 4) req() { # METHOD path [json-file] -> body(HTTP >= 400 時 exit 4;401/403 以 tea token 重試一次)
method="$1"; path="$2"; body_file="${3:-}" method="$1"; path="$2"; body_file="${3:-}"
retried=0
while :; do
if [ -n "$body_file" ]; then if [ -n "$body_file" ]; then
out=$(curl -sS -w '\n%{http_code}' -X "$method" \ out=$(curl -sS -w '\n%{http_code}' -X "$method" \
-H "Authorization: token $GITEA_TOKEN" -H "Content-Type: application/json" \ -H "Authorization: token $GITEA_TOKEN" -H "Content-Type: application/json" \
@@ -35,6 +57,12 @@ req() { # METHOD path [json-file] -> body(HTTP >= 400 時 exit 4)
-H "Authorization: token $GITEA_TOKEN" "$API$path") -H "Authorization: token $GITEA_TOKEN" "$API$path")
fi fi
code=$(printf '%s' "$out" | tail -n1) code=$(printf '%s' "$out" | tail -n1)
if [ "$retried" -eq 0 ] && { [ "$code" = 401 ] || [ "$code" = 403 ]; } \
&& [ -n "$TEA_TOKEN" ] && [ "$TEA_TOKEN" != "$GITEA_TOKEN" ]; then
GITEA_TOKEN="$TEA_TOKEN"; retried=1; continue
fi
break
done
printf '%s\n' "$out" | sed '$d' printf '%s\n' "$out" | sed '$d'
[ "$code" -lt 400 ] [ "$code" -lt 400 ]
} }