Replaces #12, which committed every generated render into the repo. Rebuilt on
a clean branch because merging the original would have written those blobs into
main's history permanently, even with a later commit deleting them.
What changed from #12:
- Keeps docs/DESIGN.md and assets/logo-mark.svg (1.4 kB of vector text).
- Drops ~23 MB of PNG/MP4. They live in the Figma file, which was already the
source of truth and is linked from the doc. stoke's .git is ~23 MB; those
assets would have doubled it, forever.
- Adds the missing "files" whitelist to package.json. There wasn't one, so
npm pack shipped the whole working directory: measured 23.7 MB with the
assets, and it was already shipping the test suite without them. Now 26.7 kB
across 7 files.
The packaging bug is pre-existing and independent of the design work; the
oversized PR is just what made it visible.
61/61 tests pass; `stoke --version` → 1.3.0.
- chmod 0644 every keyring and sources.list entry after writing: tee
inherits the caller's umask, and under e.g. umask 077 apt's
unprivileged _apt user could not read the keyring
- Tests now run the script under umask 077 and assert the 0644 modes
(mutation-checked: dropping the chmod fails a test), and remove their
temp directories on exit
- Refusal error now states that metadata was already refreshed before
concluding the existing nodesource.list is unsuitable
Verified on fresh debian:13 under umask 077: all four files 0644,
install succeeds. npm test 32/32.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Covers the scenarios codex-reviewer recommended: suitable candidate
already present (incl. epoch stripping), missing metadata healed by a
refresh, bootstrap on too-old distro nodejs, bootstrap failure, and the
refuse-to-overwrite branch for a user-managed nodesource.list. Every
scenario runs under a localized LC_ALL with an apt-cache stub that only
emits the English Candidate: label under LC_ALL=C, so locale-safe
parsing is regression-tested (mutation-checked: dropping LC_ALL=C fails
3 tests).
install-apt.sh gains STOKE_APT_ETC to redirect /etc/apt to a throwaway
directory under test, following the script's existing env-override
pattern. Real-container flow re-verified on debian:13.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- pr comment now rejects whitespace-only bodies and preserves raw body.
- pr review accepts request_changes alias in addition to request-changes.
- Add CLI-boundary regression test proving review body-file whitespace is
preserved through the CLI and sent byte-for-byte to the API.
- Update README option help text for the new alias.
- Parse apt-cache policy under LC_ALL=C (Candidate: label is localized)
- Refresh apt metadata (best effort) and re-check before concluding no
suitable nodejs source exists
- Refuse to overwrite an existing /etc/apt/sources.list.d/nodesource.list
instead of silently replacing a user-managed entry
- README: manual path now adds the forge source, then the Node 22 source,
then runs apt-get update && install — in that order
Verified on fresh debian:13: install, idempotent re-run (NodeSource not
re-added), and the refusal branch with a pre-existing user list.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The package depends on nodejs (>= 22.12), but Debian 13 ships Node 20 and
Ubuntu 24.04 ships Node 18, so a fresh container failed apt-get install
with an unmet dependency. install-apt.sh now checks whether any configured
apt source can satisfy the requirement and, if not, adds the NodeSource
Node 22 repository before installing. README documents the behaviour and
the manual equivalent.
Verified on fresh debian:13 and ubuntu:24.04 containers: one-line setup,
apt-get install stoke, stoke --version all succeed.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- Map CLI 'approve' to Forgejo's expected 'APPROVED' event.
- Require a non-empty body for request-changes and comment events.
- Update API test expectation and add CLI tests for body validation.
Adds CLI commands for inspecting a pull request, posting a comment, and
submitting an APPROVE/REQUEST_CHANGES/COMMENT review. Includes API client
methods, CLI wiring, and tests.
Implements #1 — stoke installable with apt-get install stoke.
Packaging:
- scripts/build-deb.sh: builds dist/stoke_<version>_all.deb from a clean
staging copy (src + fresh npm ci --omit=dev), pure-JS Architecture: all,
Depends: nodejs (>= 22.12), /usr/lib/stoke payload with /usr/bin/stoke
symlink, copyright + changelog, normalized permissions. Lintian-clean.
- scripts/publish-deb.sh: uploads a .deb to the Forgejo Debian registry
(owner/distribution/component parameterized, defaults heavy-duty/
stable/main), authenticating with STOKE_TOKEN or the stoke login token.
- scripts/install-apt.sh: consumer-side one-time setup — adds the
registry key and apt source, then apt-get install stoke. Falls back to
a [trusted=yes] source when apt's sqv verifier rejects the forge's
registry signature (known upstream Forgejo signing bug; the script
prefers the signed source so setups heal once the forge is fixed).
- .forgejo/workflows/release.yml: on v* tags — test, build, publish to
the heavy-duty registry, attach the .deb to the release page. Needs a
runner and a RELEASE_TOKEN secret with org package write.
New command:
- stoke pr merge (-n, --method merge|rebase|rebase-merge|squash,
--title, --message, --delete-branch) — gap found while merging !2.
Docs and housekeeping:
- README: 'Install with apt' as the primary installation method with
manual setup and dpkg fallback, signature caveat, pr merge reference,
Packaging and releasing section with a release checklist.
- dist/ gitignored; version bumped to 1.2.0.
Verified end-to-end on this machine: built the deb (lintian-clean),
published it to the Forgejo Debian registry, installed it with
apt-get install stoke via install-apt.sh, and confirmed the installed
CLI works against the live forge. The test upload was removed from the
personal namespace afterwards; publishing under heavy-duty needs an
org-member token (401 reqPackageAccess with this restricted account).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Fixes found during a full audit of the CLI:
- auth logout: remote token revocation always failed with 401 because
Forgejo only accepts Basic auth on the token endpoints. Logout now
asks for (or accepts) the account password, supports --password,
--password-file and --local-only, and clearly reports when the token
is left active.
- Silent password prompt actually echoed the password on a TTY:
overriding rl.write does not suppress readline echo. Switched to the
callback readline module and mute _writeToOutput instead (the
readline/promises interface does not honor that hook).
- Global --config flag was silently ignored: config paths were resolved
at require time, before the preAction hook set STOKE_CONFIG_FILE.
Paths are now resolved lazily on every access.
- XDG_CONFIG_HOME handling put the config in $XDG_CONFIG_HOME/.config/stoke;
per the XDG spec it now resolves to $XDG_CONFIG_HOME/stoke.
- repo create: --auto-init defaulted to true with no way to disable it;
added --no-auto-init.
- repo import/import-batch: a GitHub token was required even for
non-GitHub services (e.g. --service git), making those imports fail
without gh/GITHUB_TOKEN. Tokens are now only auto-resolved for the
github service; batch imports resolve per entry and memoize.
- Branding leftovers: 'Run: forgejo auth login' hint and
forgejo-cli/1.0.0 User-Agent now say stoke (UA tracks pkg.version).
- Added request timeouts (30s default, 10m for migrations).
- --limit and --team-id are validated as integers instead of silently
misbehaving on garbage (NaN made -l show all results).
New commands (per the repo's every-operation-becomes-a-command design):
- stoke issue create (title/body/body-file/assignees)
- stoke pr create (head/base/title/body/body-file)
Tests and metadata:
- New test suite on the built-in node:test runner (25 tests) covering
config resolution/persistence, the API client with a mocked fetch,
and end-to-end CLI behavior. npm test previously matched no files.
- package.json: engines >=22.12.0 (required by commander@15 — the
README claimed Node 18), repository, keywords, author; version 1.1.0.
- README: corrected Node requirement, documented repo rename (was
missing), issue create, pr create, logout options and revocation
caveat, --no-auto-init, XDG behavior, import token rules, testing.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
New commands, one per Forgejo API call used to set up the heavy-duty
organization membership:
- stoke user list (GET /api/v1/users/search)
- stoke user show (GET /api/v1/users/{username})
- stoke org team list (GET /api/v1/orgs/{org}/teams)
- stoke org team create (POST /api/v1/orgs/{org}/teams)
- stoke org team member-list (GET /api/v1/teams/{id}/members)
- stoke org team member-add (PUT /api/v1/teams/{id}/members/{username})
- stoke org team member-remove (DELETE /api/v1/teams/{id}/members/{username})
All commands documented in the README.
New commands, one per Forgejo API call used to move the heavy-duty
repositories into the new heavy-duty organization:
- stoke org create (POST /api/v1/orgs)
- stoke org repos (GET /api/v1/orgs/{org}/repos)
- stoke org avatar (POST /api/v1/orgs/{org}/avatar)
- stoke repo transfer (POST /api/v1/repos/{owner}/{repo}/transfer)
All commands documented in the README.