feat: add deploy tokens (#37306)

Deploy keys only work over SSH. A deploy token is their counterpart for HTTPS: a repository scoped credential, used as the password of a Git request, with read or read and write access. It covers Git operations and LFS, and can be regenerated in place.

Signed-off-by: silverwind <me@silverwind.io>
Co-authored-by: Claude Mythos <noreply@anthropic.com>
Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: bircni <bircni@icloud.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
ToastyTheBot
2026-08-26 19:32:44 +00:00
committed by GitHub
co-authored by Claude Mythos silverwind bircni wxiaoguang
parent 3c4d5a6a5c
commit 646ea0f253
76 changed files with 1592 additions and 829 deletions
+20
View File
@@ -8,6 +8,7 @@ import (
"testing"
"gitea.dev/models/db"
deploykey_model "gitea.dev/models/deploykey"
perm_model "gitea.dev/models/perm"
repo_model "gitea.dev/models/repo"
"gitea.dev/models/unittest"
@@ -101,4 +102,23 @@ func TestAuthenticate(t *testing.T) {
err := handleLFSTokenTestPerm("upload", 2, repo1, perm_model.AccessModeWrite)
assert.NoError(t, err)
})
// a deploy-key doer has no user row, so the token must carry its ext doer data to stay redeemable
t.Run("handleLFSToken resolves deploy-key doers", func(t *testing.T) {
key, err := deploykey_model.AddDeployKeyToken(t.Context(), repo1.ID, "lfs", perm_model.AccessModeRead)
require.NoError(t, err)
doer := user_model.NewDeployKeyUserWithKeyID(key.ID)
getDoerToken := func(op string) string {
s, _ := GetLFSAuthTokenWithBearer(AuthTokenOptions{Op: op, UserID: doer.ID, UserExtDoerData: doer.ExtDoerData.EncodeToString(), RepoID: repo1.ID})
_, token, _ := strings.Cut(s, " ")
return token
}
u, err := handleLFSToken(ctx, getDoerToken("download"), repo1, perm_model.AccessModeRead)
require.NoError(t, err)
assert.Equal(t, user_model.DeployKeyUserID, u.ID)
_, err = handleLFSToken(ctx, getDoerToken("upload"), repo1, perm_model.AccessModeWrite)
assert.ErrorContains(t, err, "no permission to access the repository")
})
}