fix(binjovi): grant the outline tag-protection absence read #734
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/outline-tag-protection-grant"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
binjovictl authority outlineanswersprovider_guarded · blocked · invalid_tag_protection_response, sorelease-candidatesanswers 503 and no release of sean/outline can start. Measured 2026-09-14 on sean/outline pull request 1.Forgejo.Authority.check/2reads trunk, then main, then the tag protections, and requires a**rule whitelistingbinjovi-bot. It asks that of EVERY provider-guarded project: the check proves that nobody butbinjovi-botcan move a ref in the repository, which is a different claim from "this project publishes tags". Outline's onboarding declared the two branch protections and left tags out on the reasoning that a wiki ships no tags. The branch reads passed; the tag read had nothing to return.This is the seanfarm half: the scoped
getthat lets the service worker tell an ABSENT legacyForgejoTagProtection/outline-tagsfrom a DENIED read. A name that is not in this list answers 403, every create failsdenied, and the operation is terminal after five attempts. No CR of this name has ever existed — outline came fromcreate_repository— so the read answers 404 and the worker may act. The policy row that makes it act is sean/binjovi's half.Count pin 35 → 36.
tests/binjovi-service-handoff.shgoes red without the grant and green with it.https://claude.ai/code/session_01JGe4pyhQ36AhgDfPJry4d3