From 3f0b49fa369aeca1b7baf35f886f9761109c7b30 Mon Sep 17 00:00:00 2001 From: Zakaria El Orche Date: Wed, 12 Aug 2026 20:23:18 +0000 Subject: [PATCH] ci: use a real PAT (PACKAGES_TOKEN) instead of GITEA_TOKEN for deploy MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Root cause of the persistent 401s found: Gitea's own per-job GITEA_TOKEN cannot publish to any package registry at all — a known, still- unimplemented limitation (go-gitea/gitea#23642), not a settings.xml auth-format issue as first assumed. Confirmed by testing: GITEA_TOKEN authenticated fine against the plain API but every registry write endpoint rejected it regardless of scope or header style. Co-Authored-By: Claude Sonnet 5 --- .gitea/maven-settings.xml | 20 ++++++++++---------- .gitea/workflows/publish-maven.yml | 25 ++++++------------------- 2 files changed, 16 insertions(+), 29 deletions(-) diff --git a/.gitea/maven-settings.xml b/.gitea/maven-settings.xml index 7f3e66e..fed26fe 100644 --- a/.gitea/maven-settings.xml +++ b/.gitea/maven-settings.xml @@ -3,22 +3,22 @@ xsi:schemaLocation="http://maven.apache.org/SETTINGS/1.0.0 http://maven.apache.org/xsd/settings-1.0.0.xsd"> gitea Relism - ${env.GITEA_TOKEN} + ${env.PACKAGES_TOKEN} diff --git a/.gitea/workflows/publish-maven.yml b/.gitea/workflows/publish-maven.yml index 093f997..1d4ef73 100644 --- a/.gitea/workflows/publish-maven.yml +++ b/.gitea/workflows/publish-maven.yml @@ -17,11 +17,6 @@ on: jobs: publish: runs-on: ubuntu-latest - # Deploy got a 401 without this: this repo's default Actions token permission mode is - # Restricted (read-only on packages), not Permissive — see - # https://docs.gitea.com/usage/actions/token-permissions. - permissions: - packages: write # No actions/checkout here on purpose: it's a Node-based action, and this container # (chosen for its preinstalled mvn/JDK 21) has no Node — checkout would fail with # "node: executable file not found". A plain git clone needs neither. @@ -40,22 +35,14 @@ jobs: mvn -B versions:set -DnewVersion="2.1.0-${SHORT_SHA}" -DprocessAllModules=true -DgenerateBackupPoms=false echo "Publishing as 2.1.0-${SHORT_SHA}" - # Diagnostic for the 401s seen so far: confirms GITEA_TOKEN actually reaches this step - # non-empty, and whether the token itself authenticates against the API at all — - # independent of whatever Maven/wagon-http does with it. Remove once deploy is green. - - name: Debug token - env: - GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} - run: | - apt-get install -y --no-install-recommends curl >/dev/null - echo "token length: ${#GITEA_TOKEN}" - echo "whoami via token header:" - curl -s -o /dev/null -w " token header -> %{http_code}\n" -H "Authorization: token ${GITEA_TOKEN}" https://git.pixel-services.com/api/v1/user - curl -s -o /dev/null -w " basic auth -> %{http_code}\n" -u "Relism:${GITEA_TOKEN}" https://git.pixel-services.com/api/v1/user - - name: Deploy to the Gitea Maven registry env: - GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} + # Not GITEA_TOKEN: Gitea's own job token can't publish to package registries at + # all (a known, still-unimplemented limitation — see + # https://github.com/go-gitea/gitea/issues/23642). Confirmed by testing: GITEA_TOKEN + # authenticated fine against the plain API but still got 401 from this endpoint no + # matter the auth style. PACKAGES_TOKEN is a real PAT with write:package scope. + PACKAGES_TOKEN: ${{ secrets.PACKAGES_TOKEN }} run: | mvn -B -s .gitea/maven-settings.xml -DskipTests deploy \ -DaltReleaseDeploymentRepository=gitea::https://git.pixel-services.com/api/packages/Relism/maven \