board automation: fjweb session-cookie CLI for project boards #83

Stängd
öppnade 2026-07-17 15:39:56 +00:00 av supernaut · 0 kommentarer
Ägare

Project boards have no REST API (upstream projects-API PR abandoned — re-verified during the v16 upgrade #73), so board moves were manual web-UI steps (e.g. the roadmap-to-issues board step, moving closed issues to Done).

Shipped: an internal ops CLI (fjweb) — wraps patrickzzz/forgejo-web (MIT, stdlib-only, pinned commit) and swaps its password login (disabled here — SSO-only, ADR 0020) for the operator's browser session cookie. Plus a forgejo-boards agent skill. Deliberately not headless: a bot would need reverse-proxy-auth, a security surface we are not opening (cf. #81). Cookie setup/refresh is documented with the tool internally.

Residual watch items: (a) if Forgejo ships a projects REST API, retire the tool; (b) the web routes rely on SameSite/Sec-Fetch-Site rather than CSRF tokens — a future Forgejo hardening could 403 the mutations; (c) upstream bumps only after diff review (runs with a live session).

Project boards have no REST API (upstream projects-API PR abandoned — re-verified during the v16 upgrade #73), so board moves were manual web-UI steps (e.g. the roadmap-to-issues board step, moving closed issues to Done). **Shipped:** an internal ops CLI (`fjweb`) — wraps [patrickzzz/forgejo-web](https://codeberg.org/patrickzzz/forgejo-web) (MIT, stdlib-only, pinned commit) and swaps its password login (disabled here — SSO-only, ADR 0020) for the operator's browser session cookie. Plus a `forgejo-boards` agent skill. **Deliberately not headless**: a bot would need reverse-proxy-auth, a security surface we are not opening (cf. #81). Cookie setup/refresh is documented with the tool internally. Residual watch items: (a) if Forgejo ships a projects REST API, retire the tool; (b) the web routes rely on SameSite/Sec-Fetch-Site rather than CSRF tokens — a future Forgejo hardening could 403 the mutations; (c) upstream bumps only after diff review (runs with a live session).
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#83
Ingen beskrivning angiven.