From 4638686939763853f440942d1dec0797ec97761a Mon Sep 17 00:00:00 2001 From: max-voitcov Date: Wed, 26 Aug 2026 10:30:51 +0300 Subject: [PATCH] Authenticate the npm publish with Basic, and sharpen the triage --- .gitea/workflows/release.yml | 18 +++++++++++++++++- 1 file changed, 17 insertions(+), 1 deletion(-) diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index 30966bd..c2747f8 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -108,6 +108,18 @@ jobs: curl -s -o /dev/null -w '%{http_code}\n' \ -u "${GITEA_OWNER}:$TOKEN" \ "https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/npm/@maxvojtkov%2Fpulumi-dokploy" + # A write with a deliberately empty body: 401 means the credentials + # were refused, anything else means they were accepted and only the + # payload was rejected. That is what separates "wrong token" from + # "wrong auth scheme". + echo -n "npm PUT (bearer, as npm) -> " + curl -s -o /dev/null -w '%{http_code}\n' -X PUT \ + -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \ + -d '{}' "https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/npm/@maxvojtkov%2Fpulumi-dokploy" + echo -n "npm PUT (basic) -> " + curl -s -o /dev/null -w '%{http_code}\n' -X PUT \ + -u "${GITEA_OWNER}:$TOKEN" -H 'Content-Type: application/json' \ + -d '{}' "https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/npm/@maxvojtkov%2Fpulumi-dokploy" - uses: actions/checkout@v4 with: @@ -159,9 +171,13 @@ jobs: env: TOKEN: ${{ secrets.GITEA_TOKEN }} run: | + # `_authToken` makes npm send `Authorization: Bearer`, which this + # Gitea refuses for the token Actions injects -- the publish failed + # with E401 while the very same token authenticated fine over Basic. + # `_auth` is base64 user:token, i.e. Basic. cat > .npmrc <