From d52d1060ce120abaf6ceb717554050023f9b21ef Mon Sep 17 00:00:00 2001 From: Tommy Rantti Date: Sat, 26 Sep 2026 20:05:37 +0300 Subject: [PATCH] Improve Forgejo API error reporting and add token instructions curl -f collapsed auth failures, wrong paths, and real network errors into the same vague "could not reach" message. Now reports the actual HTTP status and response body, and prompts print exactly where to generate a Forgejo access token before asking for it. Co-Authored-By: Claude Sonnet 5 --- bootstrap.sh | 37 +++++++++++++++++++++++++++++-------- 1 file changed, 29 insertions(+), 8 deletions(-) diff --git a/bootstrap.sh b/bootstrap.sh index 34ace24..b60f103 100755 --- a/bootstrap.sh +++ b/bootstrap.sh @@ -253,16 +253,30 @@ forgejo_ssh_key() { pubkey=$(cat "${keyfile}.pub") fingerprint=$(ssh-keygen -lf "${keyfile}.pub" | awk '{print $2}') + echo "Need a token: log into $FORGEJO_URL -> avatar (top right) -> Settings ->" + echo "Applications tab -> Manage Access Tokens -> name it, grant 'write:user'" + echo "scope (or tick 'user' read+write) -> Generate Token -> copy it now, it's" + echo "only shown once." local token - read -rsp "Forgejo access token (write:user scope, used once, not stored): " token + read -rsp "Forgejo access token (used once, not stored): " token echo - local existing - if ! existing=$(curl -fsS -H "Authorization: token $token" "$FORGEJO_URL/api/v1/user/keys" 2>/dev/null); then - step_fail "forgejo ssh key" "could not reach $FORGEJO_URL/api/v1/user/keys" - unset token + local tmpbody status + tmpbody=$(mktemp) + if ! status=$(curl -sS -o "$tmpbody" -w '%{http_code}' -H "Authorization: token $token" "$FORGEJO_URL/api/v1/user/keys"); then + step_fail "forgejo ssh key" "GET /api/v1/user/keys - curl could not connect at all (DNS/TLS/network)" + unset token; rm -f "$tmpbody" return fi + if [ "$status" != "200" ]; then + step_fail "forgejo ssh key" "GET /api/v1/user/keys - HTTP $status: $(cat "$tmpbody") (401=bad token, 403=missing write:user scope, 404=check FORGEJO_URL)" + unset token; rm -f "$tmpbody" + return + fi + + local existing + existing=$(cat "$tmpbody") + rm -f "$tmpbody" if echo "$existing" | jq -e --arg fp "$fingerprint" '.[] | select(.fingerprint == $fp)' >/dev/null 2>&1; then step_skip "forgejo ssh key" "already registered ($fingerprint)" @@ -274,15 +288,22 @@ forgejo_ssh_key() { payload=$(jq -n --arg title "${KEY_NAME}-$(hostname)-$(date +%Y%m%d)" --arg key "$pubkey" \ '{title: $title, key: $key}') - if curl -fsS -X POST \ + tmpbody=$(mktemp) + if ! status=$(curl -sS -o "$tmpbody" -w '%{http_code}' -X POST \ -H "Authorization: token $token" \ -H "Content-Type: application/json" \ -d "$payload" \ - "$FORGEJO_URL/api/v1/user/keys" >/dev/null; then + "$FORGEJO_URL/api/v1/user/keys"); then + step_fail "forgejo ssh key" "POST /api/v1/user/keys - curl could not connect at all (DNS/TLS/network)" + unset token; rm -f "$tmpbody" + return + fi + if [ "$status" = "200" ] || [ "$status" = "201" ]; then step_ok "forgejo ssh key" "registered ($fingerprint)" else - step_fail "forgejo ssh key" "POST to $FORGEJO_URL/api/v1/user/keys failed" + step_fail "forgejo ssh key" "POST /api/v1/user/keys - HTTP $status: $(cat "$tmpbody") (401=bad token, 403=missing write:user scope, 404=check FORGEJO_URL)" fi + rm -f "$tmpbody" unset token }