Improve Forgejo API error reporting and add token instructions

curl -f collapsed auth failures, wrong paths, and real network errors
into the same vague "could not reach" message. Now reports the actual
HTTP status and response body, and prompts print exactly where to
generate a Forgejo access token before asking for it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Tommy Rantti 2026-09-26 20:05:37 +03:00
parent 1bddb438ea
commit d52d1060ce

View file

@ -253,16 +253,30 @@ forgejo_ssh_key() {
pubkey=$(cat "${keyfile}.pub") pubkey=$(cat "${keyfile}.pub")
fingerprint=$(ssh-keygen -lf "${keyfile}.pub" | awk '{print $2}') fingerprint=$(ssh-keygen -lf "${keyfile}.pub" | awk '{print $2}')
echo "Need a token: log into $FORGEJO_URL -> avatar (top right) -> Settings ->"
echo "Applications tab -> Manage Access Tokens -> name it, grant 'write:user'"
echo "scope (or tick 'user' read+write) -> Generate Token -> copy it now, it's"
echo "only shown once."
local token local token
read -rsp "Forgejo access token (write:user scope, used once, not stored): " token read -rsp "Forgejo access token (used once, not stored): " token
echo echo
local existing local tmpbody status
if ! existing=$(curl -fsS -H "Authorization: token $token" "$FORGEJO_URL/api/v1/user/keys" 2>/dev/null); then tmpbody=$(mktemp)
step_fail "forgejo ssh key" "could not reach $FORGEJO_URL/api/v1/user/keys" if ! status=$(curl -sS -o "$tmpbody" -w '%{http_code}' -H "Authorization: token $token" "$FORGEJO_URL/api/v1/user/keys"); then
unset token step_fail "forgejo ssh key" "GET /api/v1/user/keys - curl could not connect at all (DNS/TLS/network)"
unset token; rm -f "$tmpbody"
return return
fi fi
if [ "$status" != "200" ]; then
step_fail "forgejo ssh key" "GET /api/v1/user/keys - HTTP $status: $(cat "$tmpbody") (401=bad token, 403=missing write:user scope, 404=check FORGEJO_URL)"
unset token; rm -f "$tmpbody"
return
fi
local existing
existing=$(cat "$tmpbody")
rm -f "$tmpbody"
if echo "$existing" | jq -e --arg fp "$fingerprint" '.[] | select(.fingerprint == $fp)' >/dev/null 2>&1; then if echo "$existing" | jq -e --arg fp "$fingerprint" '.[] | select(.fingerprint == $fp)' >/dev/null 2>&1; then
step_skip "forgejo ssh key" "already registered ($fingerprint)" step_skip "forgejo ssh key" "already registered ($fingerprint)"
@ -274,15 +288,22 @@ forgejo_ssh_key() {
payload=$(jq -n --arg title "${KEY_NAME}-$(hostname)-$(date +%Y%m%d)" --arg key "$pubkey" \ payload=$(jq -n --arg title "${KEY_NAME}-$(hostname)-$(date +%Y%m%d)" --arg key "$pubkey" \
'{title: $title, key: $key}') '{title: $title, key: $key}')
if curl -fsS -X POST \ tmpbody=$(mktemp)
if ! status=$(curl -sS -o "$tmpbody" -w '%{http_code}' -X POST \
-H "Authorization: token $token" \ -H "Authorization: token $token" \
-H "Content-Type: application/json" \ -H "Content-Type: application/json" \
-d "$payload" \ -d "$payload" \
"$FORGEJO_URL/api/v1/user/keys" >/dev/null; then "$FORGEJO_URL/api/v1/user/keys"); then
step_fail "forgejo ssh key" "POST /api/v1/user/keys - curl could not connect at all (DNS/TLS/network)"
unset token; rm -f "$tmpbody"
return
fi
if [ "$status" = "200" ] || [ "$status" = "201" ]; then
step_ok "forgejo ssh key" "registered ($fingerprint)" step_ok "forgejo ssh key" "registered ($fingerprint)"
else else
step_fail "forgejo ssh key" "POST to $FORGEJO_URL/api/v1/user/keys failed" step_fail "forgejo ssh key" "POST /api/v1/user/keys - HTTP $status: $(cat "$tmpbody") (401=bad token, 403=missing write:user scope, 404=check FORGEJO_URL)"
fi fi
rm -f "$tmpbody"
unset token unset token
} }