forked from heavy-duty/rig
The operator turned off REQUIRE_SIGNIN_VIEW on forgejo.heavyduty.builders, so the blocker this PR documented no longer applies to that instance. Re-measured anonymously: heavy-duty/rig, ceremony, box, cast and stoke all answer 200 on the API, the web page and git ls-remote, where rig 404'd on every one of those this morning. More to the point, the mechanism is now proven rather than argued: a credential-less templates_resolve with RIG_TEMPLATES_HOST=https://forgejo.heavyduty.builders fetches and extracts a real archive end to end. That was the one part of piece 1 that could not be demonstrated while the gate was up. The requirement itself is unchanged and the refusal text still names it — it follows from the mint's creds-free contract, not from one server's config, and any other instance hosting a registry needs the same setting. What changed is that this instance now satisfies it, so the docs say "verified satisfied" instead of "blocked". The plan doc keeps the original analysis under a heading that marks it historical: it is why the knob exists, and deleting it would lose the reasoning. forgejo#109 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| plans | ||
| templates | ||