From db28f6c1d0e1ebfbcd9a874e754bad45f6f4cb6e Mon Sep 17 00:00:00 2001 From: Jeffery Date: Tue, 25 Aug 2026 11:13:35 +0800 Subject: [PATCH 1/2] =?UTF-8?q?fix(tea-token):=20=E4=BE=9D=E4=B8=BB?= =?UTF-8?q?=E6=A9=9F=E6=8C=91=20tea=20=E7=99=BB=E5=85=A5=EF=BC=8C=E9=81=BF?= =?UTF-8?q?=E5=85=8D=E6=8A=8A=20A=20=E7=AB=99=20token=20=E9=80=81=E5=8E=BB?= =?UTF-8?q?=20B=20=E7=AB=99?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Opus 5 (1M context) --- tools/gitea.sh | 37 ++++++++++++++++++++++++++++++------- 1 file changed, 30 insertions(+), 7 deletions(-) diff --git a/tools/gitea.sh b/tools/gitea.sh index cb0e8eb..3502852 100755 --- a/tools/gitea.sh +++ b/tools/gitea.sh @@ -46,22 +46,45 @@ case "$cmd" in exit 0 ;; esac -tea_token() { # 取 tea CLI 設定檔的 token(優先 default: true 的登入,否則第一個) +tea_token() { # 取 tea CLI 設定檔的 token。$1=host-only 時,只回傳主機相符的登入 + # 優先序:url 與 $GITEA_HOST 同主機的登入 > default: true 的登入 > 第一個登入。 + # 主機比對必須排最前面:tea 可以同時登入多個站台,只看 default 會把 A 站的 + # token 送去 B 站——那是憑證外洩,不是單純的取錯值。 cfg="${HOME}/.config/tea/config.yml" [ -f "$cfg" ] || return 1 - t=$(awk ' - /^ *- / { if (def && tok != "") { print tok; found=1; exit } tok=""; def=0 } - /^ *token: */ { line=$0; sub(/^ *token: */,"",line); gsub(/"/,"",line) - tok=line; if (first=="") first=line } + only_host="${1:-}" + want=$(printf '%s' "${GITEA_HOST:-}" | sed 's#^https\{0,1\}://##; s#/.*##') + t=$(awk -v want="$want" -v only_host="$only_host" ' + function flush() { + if (tok == "") return + if (first == "") first = tok + if (want != "" && host == want) { match_tok = tok } + if (def) def_tok = tok + } + /^ *- / { flush(); tok=""; host=""; def=0 } + /^ *token: */ { line=$0; sub(/^ *token: */,"",line); gsub(/"/,"",line); tok=line } + /^ *url: */ { line=$0; sub(/^ *url: */,"",line); gsub(/"/,"",line) + sub(/^https?:\/\//,"",line); sub(/\/.*$/,"",line); host=line } /^ *default: *true/ { def=1 } - END { if (!found) { if (def && tok != "") print tok; else print first } } + END { + flush() + if (match_tok != "") { print match_tok; exit } + if (only_host == "host-only") exit + if (def_tok != "") print def_tok + else print first + } ' "$cfg") [ -n "$t" ] && printf '%s\n' "$t" } : "${GITEA_HOST:?GITEA_HOST is required}" TEA_TOKEN=$(tea_token 2>/dev/null || true) -if [ -z "${GITEA_TOKEN:-}" ]; then +TEA_HOST_TOKEN=$(tea_token host-only 2>/dev/null || true) +if [ -n "$TEA_HOST_TOKEN" ]; then + # tea 有這個主機的專用登入就優先用它。$GITEA_TOKEN 是通用變數,未必屬於 + # 這次要連的主機;把它送去別的站等於憑證外洩,比取錯值嚴重得多。 + GITEA_TOKEN="$TEA_HOST_TOKEN" +elif [ -z "${GITEA_TOKEN:-}" ]; then if [ -n "$TEA_TOKEN" ]; then GITEA_TOKEN="$TEA_TOKEN"; else : "${GITEA_TOKEN:?GITEA_TOKEN is required}" fi -- 2.53.0 From 13c449c4dec964bf81e987d518ac88dee9c1e8cb Mon Sep 17 00:00:00 2001 From: Jeffery Date: Tue, 25 Aug 2026 11:13:35 +0800 Subject: [PATCH 2/2] =?UTF-8?q?chore(plugin=20=E7=89=88=E6=9C=AC):=20?= =?UTF-8?q?=E4=B8=89=E4=BB=BD=20manifest=20=E5=8D=87=E7=89=88=E8=87=B3=200?= =?UTF-8?q?.0.9?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Opus 5 (1M context) --- .claude-plugin/plugin.json | 2 +- .codex-plugin/plugin.json | 2 +- plugin.json | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.claude-plugin/plugin.json b/.claude-plugin/plugin.json index 4a302c8..4732f37 100644 --- a/.claude-plugin/plugin.json +++ b/.claude-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "jsc-gitea", - "version": "0.0.8", + "version": "0.0.9", "description": "Gitea API 工具、Wiki 讀寫與存取庫批次同步", "skills": "./skills", "author": { diff --git a/.codex-plugin/plugin.json b/.codex-plugin/plugin.json index e04331f..46895bd 100644 --- a/.codex-plugin/plugin.json +++ b/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "jsc-gitea", - "version": "0.0.8", + "version": "0.0.9", "description": "Gitea API 工具、Wiki 讀寫與存取庫批次同步", "skills": "./skills" } diff --git a/plugin.json b/plugin.json index 663cfe1..b6739f4 100644 --- a/plugin.json +++ b/plugin.json @@ -1,6 +1,6 @@ { "name": "jsc-gitea", - "version": "0.0.8", + "version": "0.0.9", "description": "Gitea API 工具、Wiki 讀寫與存取庫批次同步", "skills": "./skills/" } -- 2.53.0