You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
gitea/services
Giteabot d2efd2bf73
Require repo scope for PATs for private repos and basic authentication (#24362) (#24364)
Backport #24362 by @jolheiser

> The scoped token PR just checked all API routes but in fact, some web
routes like `LFS`, git `HTTP`, container, and attachments supports basic
auth. This PR added scoped token check for them.

Signed-off-by: jolheiser <john.olheiser@gmail.com>
Co-authored-by: John Olheiser <john.olheiser@gmail.com>
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
2 years ago
..
actions Handle canceled workflow as a warning instead of a fail (#24282) (#24292) 2 years ago
agit Rename almost all Ctx functions (#22071) 2 years ago
asymkey Add context cache as a request level cache (#22294) 2 years ago
attachment Preserve file size when creating attachments (#23406) (#23426) 2 years ago
auth Require repo scope for PATs for private repos and basic authentication (#24362) (#24364) 2 years ago
automerge Add force_merge to merge request and fix checking mergable (#23010) 2 years ago
context Use User.ID instead of User.Name in ActivityPub API for Person IRI (#23823) (#23905) 2 years ago
convert Fix SyncOnCommit always return false in API of push_mirrors (#23088) (#23100) 2 years ago
cron Add Cargo package registry (#21888) 2 years ago
externalaccount Implement FSFE REUSE for golang files (#21840) 2 years ago
forms Title can be empty when creating tag only (#23917) (#23961) 2 years ago
gitdiff Fix broken code editor diff preview (#23307) (#23320) 2 years ago
issue Fix issue attachment handling (#24202) (#24221) 2 years ago
lfs Require repo scope for PATs for private repos and basic authentication (#24362) (#24364) 2 years ago
mailer Preserve file size when creating attachments (#23406) (#23426) 2 years ago
markup Implement FSFE REUSE for golang files (#21840) 2 years ago
migrations Add loading yaml label template files (#22976) (#23232) 2 years ago
mirror Fill head commit to in payload when notifying push commits for mirroring (#23215) (#23292) 2 years ago
org Implement FSFE REUSE for golang files (#21840) 2 years ago
packages Use import of OCI structs (#22765) 2 years ago
pull [Patch] Fix closed PR also triggers Webhooks and actions (#23782) (#23834) 2 years ago
release Delete deleted release attachments immediately from storage (#23913) (#23958) 2 years ago
repository Make label templates have consistent behavior and priority (#23749) (#24071) 2 years ago
task Implement FSFE REUSE for golang files (#21840) 2 years ago
user Add context cache as a request level cache (#22294) 2 years ago
webhook Fix incorrect `HookEventType` of pull request review comments (#23650) (#23678) 2 years ago
wiki Fix bug when deleting wiki with no code write permission (#24274) (#24295) 2 years ago