From 18ec0ab0ff30c99bf846d1ddde7b97f9303fe4f7 Mon Sep 17 00:00:00 2001 From: Defame1297 Date: Sun, 5 Jul 2026 19:12:09 +0000 Subject: [PATCH] fix(gitea): correct token-scope claim in gitea-branches docs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit SKILL.md, README.md, and references/{branches,commits}.md claimed list_branches, list_commits, and get_commit "work with write:issue alone." This contradicted docs/research/docs/gitea/overview.md, which documents write:repository as gating both reads and writes for repo-scoped tool families (Gitea hides these reads behind write scope). The prior empirical justification was invalid: it tested under a token holding both write:issue and write:repository simultaneously, which doesn't isolate which scope actually enabled the reads. Corrected all four files to state that list_branches, create_branch, and delete_branch require write:repository, confirmed directly by overview.md's scope enumeration. list_commits/get_commit are flagged as inferred to need the same scope by analogy rather than an overview.md-confirmed fact, since overview.md's write:repository enumeration names PR/branch/file/release/tag but not commits — this distinction surfaced during an independent audit pass and is now called out explicitly so the claim isn't overstated. Bumped SKILL.md metadata.version 0.1.0 -> 0.1.1 (patch: doc correction, no behavior change). --- plugins/gitea/skills/gitea-branches/README.md | 8 +++++--- plugins/gitea/skills/gitea-branches/SKILL.md | 4 ++-- .../gitea/skills/gitea-branches/references/branches.md | 9 ++++++--- .../gitea/skills/gitea-branches/references/commits.md | 10 ++++++++-- 4 files changed, 21 insertions(+), 10 deletions(-) diff --git a/plugins/gitea/skills/gitea-branches/README.md b/plugins/gitea/skills/gitea-branches/README.md index c84e765..1be8bcc 100644 --- a/plugins/gitea/skills/gitea-branches/README.md +++ b/plugins/gitea/skills/gitea-branches/README.md @@ -12,9 +12,11 @@ explicit confirmation, and treating unexpected 404s as possible masked 403s). ## Before you start -Requires a Gitea MCP server configured with a token. `list_branches`, `list_commits`, and -`get_commit` work with `write:issue` alone; `create_branch` and `delete_branch` need -`write:repository`. Requires a git remote named `origin` pointing at the Gitea instance. +Requires a Gitea MCP server configured with a token that has `write:repository` scope. This is +confirmed for `list_branches`, `create_branch`, and `delete_branch` (Gitea gates reads behind write +scope for repo-scoped operations); `list_commits` and `get_commit` are inferred to need the same +scope by analogy, not explicitly confirmed — see `references/commits.md`. Requires a git remote +named `origin` pointing at the Gitea instance. ## Usage diff --git a/plugins/gitea/skills/gitea-branches/SKILL.md b/plugins/gitea/skills/gitea-branches/SKILL.md index 0daa079..654ebfc 100644 --- a/plugins/gitea/skills/gitea-branches/SKILL.md +++ b/plugins/gitea/skills/gitea-branches/SKILL.md @@ -13,11 +13,11 @@ description: > git-history) or for PR-side branch references like cross-repo fork PR heads (use gitea-prs). -compatibility: Requires Gitea MCP server configured with a token; list_branches, list_commits, and get_commit work with write:issue alone, create_branch and delete_branch require write:repository. Requires git remote "origin" pointing to the Gitea instance. +compatibility: Requires Gitea MCP server configured with a token with write:repository scope; this is confirmed to gate list_branches, create_branch, and delete_branch (Gitea gates reads behind write scope for repo-scoped operations), and is inferred by analogy (not explicitly confirmed by source docs) to also gate list_commits and get_commit. Requires git remote "origin" pointing to the Gitea instance. metadata: category: integration - version: "0.1.0" + version: "0.1.1" source_keys: - gitea-mcp-repo - gitea-mcp-slim-go diff --git a/plugins/gitea/skills/gitea-branches/references/branches.md b/plugins/gitea/skills/gitea-branches/references/branches.md index 1c995b3..b94754d 100644 --- a/plugins/gitea/skills/gitea-branches/references/branches.md +++ b/plugins/gitea/skills/gitea-branches/references/branches.md @@ -73,6 +73,9 @@ protected, every time, regardless of how the request is phrased. ## Token scope -`list_branches` works with `write:issue` alone. `create_branch` and `delete_branch` need -`write:repository`. All three are verified working empirically under a token with both scopes -(`write:issue` + `write:repository`). +All three — `list_branches`, `create_branch`, `delete_branch` — require `write:repository`. Gitea +gates reads behind write scope for repo-scoped operations, so `list_branches` needs the same scope +as the write operations, not `write:issue` alone. An earlier version of this doc claimed +`write:issue` alone was sufficient for `list_branches`, based on empirical testing under a token +that held both `write:issue` and `write:repository` simultaneously — that test didn't isolate the +variable, so it couldn't actually establish `write:issue` alone as sufficient. diff --git a/plugins/gitea/skills/gitea-branches/references/commits.md b/plugins/gitea/skills/gitea-branches/references/commits.md index b63d426..fddeff5 100644 --- a/plugins/gitea/skills/gitea-branches/references/commits.md +++ b/plugins/gitea/skills/gitea-branches/references/commits.md @@ -63,5 +63,11 @@ edge cases, `get_commit` will not. ## Token scope -Both tools are read-only and work with `write:issue` alone (no `write:repository` needed), verified -empirically against the deployed server. +Both tools are believed to require `write:repository`, even though they're read-only — inferred by +analogy with the scope-gating principle in `overview.md` (Gitea gates reads behind write scope for +repo-scoped operations), not a claim `overview.md` makes for commits by name: its explicit +`write:repository` enumeration lists PR, branch, file, release, and tag operations, but doesn't +mention commits. An earlier version of this doc claimed `write:issue` alone worked, based on +empirical testing under a token that held both `write:issue` and `write:repository` +simultaneously — that test didn't isolate the variable either. Treat this as unverified until +tested under a token scoped to `write:issue` only (no `write:repository`).