Commit Graph
21591 Commits
Author SHA1 Message Date
fce7b9d531 fix: package registry keypair creation race (#39319)
Alpine, arch, debian, and rpm package types have a race in key creation.

---------

Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
2026-09-18 18:30:27 +00:00
b27e7d0289 enhance: improve issue-pattern capture groups and support both internal&external trackers enabled (#39354)
* Fix #39351
* Fix #17621
* Fix #34881

By the way, fix error handling bugs in `updateRepoUnits`

---------

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-18 08:53:45 -07:00
silverwindandGitHub 85eaf5c71c refactor(api): convert bot accounts through the admin user edit endpoint (#39355)
Follow-up to https://github.com/go-gitea/gitea/pull/38966. Replaces the
unreleased `POST /admin/users/{username}/convert-type` endpoint with a
`type` field on `PATCH /admin/users/{username}`.
2026-09-18 17:11:56 +02:00
3bec08f998 feat: manage bot accounts from the admin UI, API and CLI (#38966)
Adds first-class bot accounts (`UserTypeBot`): local, password-less
users for automation that authenticate only with access tokens.

1. Admin UI: create bots, filter users by type, manage a bot's access
tokens, convert between user and bot
2. API: `POST /admin/users/{username}/convert-type`, and user objects
gain a GitHub-compatible `type` (`User`, `Organization`, `Bot`)
3. CLI: `gitea admin user change-type`, `--user-type` accepts `User` or
`Bot` case-insensitively
4. Converting keeps the password, 2FA, OAuth2 grants and access tokens,
and since sign-in rejects bots, converting back restores the account.
Only local, non-admin accounts can be converted, and conversions are
audited
5. Session, reverse proxy, SSPI, external source and password reset
sign-in reject non-individual users, so a bot never gets an interactive
session
6. Bots receive no notifications or emails

Co-authored-by: Nicolas <bircni@icloud.com>
Co-authored-by: joestump <joe@joestump.net>
Co-authored-by: Joe Stump <joe@stu.mp>
Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
2026-09-18 12:43:36 +00:00
silverwindandGitHub db7dbd5a6b test: stop tests from writing into ~/.ssh (#39348) 2026-09-18 17:07:45 +08:00
GiteaBot 6400c1545e [skip ci] Updated translations via Crowdin 2026-09-18 00:54:14 +00:00
silverwindandGitHub 2b10f77e42 enhance: update mermaid to v12 (#39331)
Update to [mermaid
v12](https://github.com/mermaid-js/mermaid/releases#release-mermaid@12.0.0),
ELK is now the default layout so the plugin and all supporting code is
gone.

Layout switching to previous `dagre` layout via frontmatter works as
expected. Diagrams use the new `neo` default look which renders them
slightly different (smaller boxes) then the `classic` look that was
default in v11.

The `neo` look got some tweaks to remove shadows and gradient to look
better. Also did some related refactors and mermaid dragging now works
on touch devices too.
2026-09-17 23:28:51 +00:00
Roshan RamaniandGitHub c0c573f7af docs: correct ALLOW_LOCALNETWORKS description in app.example.ini (#39240)
Fixes the `app.example.ini` half of #39224.

The comment says:

> If a domain is allowed by `ALLOWED_DOMAINS`, this option will be
ignored.

That is no longer true. `checkByAllowBlockList` in
`services/migrations/migrate.go` consults the block list **first** and
returns immediately:

```go
if blockList.MatchHostName(hostName) || ipBlocked {
    return &git.ErrInvalidCloneAddr{Host: hostName, IsPermissionDenied: true}
}
// if we have an allow-list, check the allow-list before return to get the more accurate error
if !allowList.IsEmpty() { ... }
```

`IsMigrateURLAllowed` resolves the host with `net.LookupIP` and passes
the addresses in, so with `ALLOW_LOCALNETWORKS = false` a host that
appears in `ALLOWED_DOMAINS` is still rejected once any resolved address
is private or loopback — the allow list never gets a look. The reporter
traced this to the validation hardening in #38324 / #38400, and the code
matches their description.

The new wording states the precedence rather than the old override
claim.

Scope: this only covers `custom/conf/app.example.ini`, which lives here.
The same stale sentence is on the config cheat sheet in `gitea/docs`
(both the English and zh-cn pages) per the issue; that is a separate
repository.

Assisted-by: Claude, via Claude Code
2026-09-17 12:23:40 -07:00
4892a55e29 enhance: allow attribute-less MathML elements and complete the Core allowlist (#39337)
Follow-up to https://github.com/go-gitea/gitea/pull/38034.

---------

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-17 13:18:33 +00:00
Zhaoqi XuandGitHub be7cde7539 fix(repo): surface unrelated histories on Sync Fork (#39258)
Sync Fork already maps merge conflicts to a JSON error. Unrelated
histories still went through `ServerError`, so the UI showed a 500 HTML
snippet instead of the same user-facing message PR merge already uses
(`repo.pulls.unrelated_histories`).

The API path returned 500 for the same git error; PR merge returns 409.
Match that.

Fixes #36772

AI assistance was used to locate the handler gap and draft the mapping.
I reviewed and take responsibility for the change.

Signed-off-by: Zhaoqi Xu <lzy00419@outlook.com>
2026-09-17 12:25:43 +00:00
silverwindandGitHub afb7edef07 refactor: replace AWS SDK with a REST client for CodeCommit migration (#39330)
Replace `aws-sdk-go-v2` in the CodeCommit migration with a minimal REST
client for the four read-only API calls it uses. Binary shrinks by ~3.1
MB.

Mock data was recorded against live from a AWS CodeCommit repo and then
anonymized.

Also stop storing the repo description as the default branch which fixes
below issue. All comments in
https://github.com/go-gitea/gitea/issues/34627 are addressed, the merge
metadata was fixed earlier in
https://github.com/go-gitea/gitea/pull/34645.

Fixes: https://github.com/go-gitea/gitea/issues/34627
2026-09-17 09:58:05 +00:00
silverwindandGitHub e77d3bffae perf(frontend): enable vite module preload (#39332)
`modulePreload: false` came in with the webpack to vite migration, when
chunks were cache-busted through import maps. With content-hashed chunks
that reason is gone. Vite's default makes every lazy import preload its
whole static dependency tree in parallel instead of the browser
discovering it one level per round trip, which renders lazy features like
mermaid, the code editor and the activity charts noticeably faster on
real-world latency without changing chunks or requests.

Assisted-by: Claude Code:claude-opus-5
2026-09-17 11:22:53 +02:00
GiteaBot f0d2195998 [skip ci] Updated translations via Crowdin 2026-09-17 00:54:44 +00:00
b2e11ddb37 fix: add default timeout and handle errors for HaveIBeenPwned API (#39316)
Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-16 20:41:57 +02:00
7ebb2caa9e fix(user): unify email validation for registration and settings (#39304)
Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-16 17:34:41 +00:00
c6c671e113 refactor: replace Azure Blob SDK with a REST client (#39315)
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-16 17:06:00 +02:00
wxiaoguangandGitHub f0a535b641 build(gogit): disable gogit builds for stable releases (#39324) 2026-09-16 13:36:10 +00:00
silverwindandGitHub 2b6500aca4 test(e2e): log out to switch users in pr-review test (#39328) 2026-09-16 15:32:02 +02:00
c04802b6b3 enhance: support ETag on streamed repository archives, support If-None-Match: * (#39289)
Signed-off-by: silverwind <me@silverwind.io>
Co-authored-by: Claude (Opus 5) <noreply@anthropic.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-16 12:30:22 +02:00
31b4d79a84 fix: match install page update checker setting with app.ini (#39317)
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-16 07:47:34 +00:00
silverwindandGitHub 7efd24b28f fix(actions): use gitea's clock for actions durations (#39323) 2026-09-16 06:53:15 +00:00
GiteaBot 62945266d4 [skip ci] Updated translations via Crowdin 2026-09-16 00:55:08 +00:00
a583a30d4a enhance(notifications): mark current notification page as read (#39294)
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-16 00:31:16 +00:00
silverwindandGitHub f9d3268dbe fix(actions): never show negative running durations (#39322) 2026-09-15 21:33:17 +02:00
812191c0f9 fix: classify git failures on stderr, restrict migration failure detail (#39010)
Signed-off-by: silverwind <me@silverwind.io>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-15 10:59:34 +02:00
GiteaBot 7b036e96c2 [skip ci] Updated translations via Crowdin 2026-09-15 00:55:42 +00:00
c0ceea2f8f chore: fix various problems (#39298)
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
2026-09-14 22:15:21 +02:00
85cbf477e5 fix: correct stdErr match in isErrBlameNotFoundOrNotEnoughLines (#39309)
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-14 14:59:18 +00:00
13033827b1 chore(deps): update actionslib to v1.0.0 (#39295)
Co-authored-by: bircni <bircni@icloud.com>
2026-09-14 16:29:31 +02:00
cefb81a16f chore(deps): update dependencies (#39306)
Co-authored-by: silverwind <me@silverwind.io>
2026-09-14 13:18:00 +00:00
GiteaBot 25984bef0f [skip ci] Updated translations via Crowdin 2026-09-14 00:59:43 +00:00
GiteaBot 4ed7020d07 [skip ci] Updated translations via Crowdin 2026-09-13 01:00:55 +00:00
wxiaoguangandGitHub 1280de5704 chore: fix system users (#39299) 2026-09-12 16:26:20 +00:00
1e13badb39 enhance: truncate but show long lines in diffs (#39279)
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-12 11:56:25 +00:00
da37b7916b feat: Add audit logging (#38189)
Co-authored-by: bircni <bircni@users.noreply.github.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-12 08:15:23 +00:00
GiteaBot 4d43445532 [skip ci] Updated translations via Crowdin 2026-09-11 00:52:31 +00:00
k3nandGitHub 8c0911669b fix(ui): use button elements for branch and tag dropdown tabs (#39285)
Signed-off-by: Francesco Passaquindici <k3n.solver@gmail.com>
2026-09-10 20:51:23 +00:00
40385ef284 fix(projects): allow max columns to the limit (#39272)
Signed-off-by: Petr Vaněk <pevadev@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
2026-09-10 22:32:46 +02:00
GiteaBot 579de92b8a [skip ci] Updated translations via Crowdin 2026-09-10 00:53:46 +00:00
79fc119641 fix(auth): fix ssh and gpg key verification on windows (#39283)
Signed-off-by: Francesco Passaquindici <k3n.solver@gmail.com>
Signed-off-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-09 20:42:29 +00:00
81dee529ed enhance: improve e-mail templates (#38396)
Co-authored-by: bircni <bircni@icloud.com>
2026-09-09 17:58:27 +00:00
GiteaBot 92f2f6161b [skip ci] Updated translations via Crowdin 2026-09-09 00:54:44 +00:00
silverwindandGitHub f5c7b21f1d refactor(templates): update djlint to 1.46.0 and resolve its new findings (#39231) 2026-09-08 23:17:17 +00:00
459fc13783 enhance(packages): implement npm single-version API and add per-version repository (#39267)
Signed-off-by: silverwind <me@silverwind.io>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
2026-09-08 18:25:29 +00:00
Harsh SharmaandGitHub d93bd06d0c fix: allow re-requesting uncounted review approvals (#38988) 2026-09-08 15:59:06 +00:00
c9193adb68 fix: restore owner name in PR target branch selector (#39262)
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-08 15:34:49 +00:00
wxiaoguangandGitHub 45a78bbc8e refactor: npm route handlers (#39275) 2026-09-08 15:15:40 +00:00
8b6ad49a5f fix(api): enforce mustNotBeArchived on repo topics routes (#39260)
Co-authored-by: silverwind <me@silverwind.io>
2026-09-08 09:28:57 +00:00
silverwindandGitHub df8e7db02f test: release fixtures loader lock before database work (#39263) 2026-09-08 11:10:14 +02:00
GiteaBot e8254bd5c1 [skip ci] Updated translations via Crowdin 2026-09-08 00:55:59 +00:00