mhoennigandClaude a734d91918 Stop embedding the control token in every page (v0.9.10)
Closes TODO 2 of the security audit in docs/prs/2026-07-08-PR#000.

Every rendered page carried the live control token in a meta tag so that
gittally.js could send it, but no GET is authenticated — so `curl … |
grep gittally-control-token` handed the token to anyone, and read access
was effectively write access.

Reading stays fully public, which is a requirement rather than an
oversight: build states, logs and artifacts must be linkable from Gitea,
chats or tickets without a login. Only the distribution of the token
changed. The meta tag is gone; gittally.js keeps the token in
localStorage and asks for it once per browser, so knowing it requires
shell access to `.git/gittally/control-token` on the host. A token the
server rejects is dropped and asked for once more, so a rotated secret is
not a dead end. As a request header it stays inherently CSRF-safe.

The five branches of that flow (first use, reuse, stale token, cancelled
prompt, wrong token twice) were exercised against the real source with a
throwaway node harness; the UI test now asserts the token does not appear
in the rendered page. `docs/deployment.md` gained a "Control Token"
section on the public-read/token-protected-write split.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-11 08:00:09 +02:00
2026-06-09 14:31:35 +02:00
2026-06-09 11:55:23 +02:00
2026-06-09 11:55:23 +02:00
2026-06-09 09:07:47 +02:00
2026-06-09 11:55:23 +02:00

GitTally

Lightweight, declarative and highly opinionated software build system (CI/CD).

Documentation

Legacy Script

legacy/gitTally (bash) is deprecated and kept only as a behavioral reference for the rewrite. Do not use it for new installations; see docs/migration-from-legacy.md.

Developer Setup

Source .envrc to add tools/ to your PATH, or install direnv to have this done automatically on cd:

source .envrc

Common tasks:

./gradlew build          # compile and run all checks
./gradlew test           # run tests
./gradlew ktlintFormat   # auto-format Kotlin sources
./gradlew ktlintCheck    # check formatting (also runs as part of build)

adr-status               # show all architecture decisions at a glance

direnv

direnv sources .envrc automatically whenever you enter the repository and unloads it when you leave.

# Ubuntu
sudo apt install direnv

# add to ~/.bashrc or ~/.zshrc
eval "$(direnv hook bash)"   # or: eval "$(direnv hook zsh)"

Trust the project's .envrc once per clone:

direnv allow

Tools (tools/)

Command Description
adr-status List all Architecture Decision Records with their status and decision summary

Architecture Decision Records

Major technical decisions are documented as ADRs in docs/adrs/.

adr-status   # show all decisions at a glance

New ADRs follow the template at docs/adrs/0000-00-00.adr-template.md.

S
Description
A simple CI app mostly for GitEA and Hostsharing Managed Webserver/Webspace as well as Hostsharing Container Server.
Readme MIT
5 MiB
Languages
Kotlin 87%
HTML 4.6%
Shell 4.2%
JavaScript 3%
CSS 1.2%