update-app.sh: authenticated pull via ~/.config/shonar-desktop/forgejo.token (chmod 600, outside the repo) — one-click in-app update works without interactive credentials; anonymous pull kept as fallback when no token file

This commit is contained in:
avi 2026-09-23 14:56:04 -05:00
commit 205342bcbc

View file

@ -17,7 +17,17 @@ echo "=== update started $(date -Is) ==="
cd "$repo" || { echo "no repo at $repo"; exit 1; }
if ! git pull atitlan master; then
# Authenticated pull: the forgejo remote needs a Basic-token header per use.
# The token lives OUTSIDE the repo at ~/.config/shonar-desktop/forgejo.token
# (chmod 600, never committed); without it we still try an anonymous pull.
auth=()
tokfile="$HOME/.config/shonar-desktop/forgejo.token"
if [ -s "$tokfile" ]; then
tok="$(cat "$tokfile")"
auth=(-c "http.extraHeader=Authorization: Basic $(printf 'avi:%s' "$tok" | base64 -w0)")
fi
if ! git "${auth[@]}" pull atitlan master; then
echo "git pull FAILED — leaving the running app alone"
exit 1
fi