board automation: fjweb session-cookie CLI for project boards #83
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#83
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Project boards have no REST API (upstream projects-API PR abandoned — re-verified during the v16 upgrade #73), so board moves were manual web-UI steps (e.g. the roadmap-to-issues board step, moving closed issues to Done).
Shipped: an internal ops CLI (
fjweb) — wraps patrickzzz/forgejo-web (MIT, stdlib-only, pinned commit) and swaps its password login (disabled here — SSO-only, ADR 0020) for the operator's browser session cookie. Plus aforgejo-boardsagent skill. Deliberately not headless: a bot would need reverse-proxy-auth, a security surface we are not opening (cf. #81). Cookie setup/refresh is documented with the tool internally.Residual watch items: (a) if Forgejo ships a projects REST API, retire the tool; (b) the web routes rely on SameSite/Sec-Fetch-Site rather than CSRF tokens — a future Forgejo hardening could 403 the mutations; (c) upstream bumps only after diff review (runs with a live session).