From 205342bcbcff0d044a7a34f1e304e954480874c5 Mon Sep 17 00:00:00 2001 From: avi Date: Wed, 23 Sep 2026 14:56:04 -0500 Subject: [PATCH] =?UTF-8?q?update-app.sh:=20authenticated=20pull=20via=20~?= =?UTF-8?q?/.config/shonar-desktop/forgejo.token=20(chmod=20600,=20outside?= =?UTF-8?q?=20the=20repo)=20=E2=80=94=20one-click=20in-app=20update=20work?= =?UTF-8?q?s=20without=20interactive=20credentials;=20anonymous=20pull=20k?= =?UTF-8?q?ept=20as=20fallback=20when=20no=20token=20file?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- scripts/update-app.sh | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/scripts/update-app.sh b/scripts/update-app.sh index 7fec441..6cb24bb 100755 --- a/scripts/update-app.sh +++ b/scripts/update-app.sh @@ -17,7 +17,17 @@ echo "=== update started $(date -Is) ===" cd "$repo" || { echo "no repo at $repo"; exit 1; } -if ! git pull atitlan master; then +# Authenticated pull: the forgejo remote needs a Basic-token header per use. +# The token lives OUTSIDE the repo at ~/.config/shonar-desktop/forgejo.token +# (chmod 600, never committed); without it we still try an anonymous pull. +auth=() +tokfile="$HOME/.config/shonar-desktop/forgejo.token" +if [ -s "$tokfile" ]; then + tok="$(cat "$tokfile")" + auth=(-c "http.extraHeader=Authorization: Basic $(printf 'avi:%s' "$tok" | base64 -w0)") +fi + +if ! git "${auth[@]}" pull atitlan master; then echo "git pull FAILED — leaving the running app alone" exit 1 fi