feat: add deploy tokens (#37306)

Deploy keys only work over SSH. A deploy token is their counterpart for HTTPS: a repository scoped credential, used as the password of a Git request, with read or read and write access. It covers Git operations and LFS, and can be regenerated in place.

Signed-off-by: silverwind <me@silverwind.io>
Co-authored-by: Claude Mythos <noreply@anthropic.com>
Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: bircni <bircni@icloud.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
ToastyTheBot
2026-08-27 03:32:44 +08:00
committed by GitHub
parent 3c4d5a6a5c
commit 646ea0f253
76 changed files with 1594 additions and 831 deletions
+46
View File
@@ -0,0 +1,46 @@
// Copyright 2026 The Gitea Authors. All rights reserved.
// SPDX-License-Identifier: MIT
package user
import (
"strconv"
"strings"
)
type ExtDoerData interface {
EncodeToString() string
DecodeFromString(string) error
}
type extDoerGiteaActions struct {
TaskID int64
}
var _ ExtDoerData = (*extDoerGiteaActions)(nil)
func (e *extDoerGiteaActions) EncodeToString() string {
return "gitea-actions:" + strconv.FormatInt(e.TaskID, 10)
}
func (e *extDoerGiteaActions) DecodeFromString(s string) (err error) {
idStr, _ := strings.CutPrefix(s, "gitea-actions:")
e.TaskID, err = strconv.ParseInt(idStr, 10, 64)
return err
}
type extDoerDeployKey struct {
DeployKeyID int64
}
var _ ExtDoerData = (*extDoerDeployKey)(nil)
func (e *extDoerDeployKey) EncodeToString() string {
return "deploy-key:" + strconv.FormatInt(e.DeployKeyID, 10)
}
func (e *extDoerDeployKey) DecodeFromString(s string) (err error) {
idStr, _ := strings.CutPrefix(s, "deploy-key:")
e.DeployKeyID, err = strconv.ParseInt(idStr, 10, 64)
return err
}