diff --git a/.gitea/workflows/pr-checks.yml b/.gitea/workflows/pr-checks.yml index b0859a5..be8783a 100644 --- a/.gitea/workflows/pr-checks.yml +++ b/.gitea/workflows/pr-checks.yml @@ -178,7 +178,9 @@ jobs: - name: Review PR diff with Claude Code env: CLAUDE_CODE_OAUTH_TOKEN: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} - GITEA_TOKEN: ${{ secrets.REGISTRY_TOKEN }} + # Auto-provided per-run token from Gitea Actions (repo-scoped). + # GITHUB_TOKEN is the documented name; GITEA_TOKEN is its alias. + GITEA_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITEA_SERVER_URL: ${{ gitea.server_url }} GITEA_REPOSITORY: ${{ gitea.repository }} PR_NUMBER: ${{ gitea.event.pull_request.number }} diff --git a/docs/DEPLOY.md b/docs/DEPLOY.md index e7ca948..6080777 100644 --- a/docs/DEPLOY.md +++ b/docs/DEPLOY.md @@ -56,7 +56,7 @@ fail the E2E gate. That's the point: staging absorbs the risk. | Secret | Purpose | |---|---| -| `REGISTRY_TOKEN` | push images to the registry + post PR review comments (already set) | +| `REGISTRY_TOKEN` | push images to privaterepo.sitaru.org (already set) | | `CLAUDE_CODE_OAUTH_TOKEN` | Claude Code subscription auth for the PR review — generate with `claude setup-token` on your machine | | `PORTAINER_STAGING_WEBHOOK` | staging stack redeploy webhook URL | | `PORTAINER_PROD_WEBHOOK` | production stack redeploy webhook URL | @@ -125,7 +125,8 @@ numbers, so scheduled data refreshes don't break the gate. `scripts/ci/ai_review.py` pipes the PR diff through headless Claude Code (`claude -p`, authenticated with the subscription OAuth token — no API -billing), posts the structured findings as a PR comment via the Gitea API -(reusing `REGISTRY_TOKEN`), and fails the check only when a finding is rated +billing), posts the structured findings as a PR comment using the per-run +token Gitea Actions provides automatically (`secrets.GITEA_TOKEN` — no setup +needed), and fails the check only when a finding is rated **severe** (would break prod, leak data, or corrupt data). Minor findings are informational and never block a merge. diff --git a/nextjs-app/app/layout.tsx b/nextjs-app/app/layout.tsx index 0ee5b9b..82e7c55 100644 --- a/nextjs-app/app/layout.tsx +++ b/nextjs-app/app/layout.tsx @@ -76,9 +76,12 @@ export default function RootLayout({ + {/* data-domains: the tracker only fires on the production hostnames, + so staging (same image, different host) never pollutes Umami */}