Fix #502: anonymous write interstitial #507
No reviewers
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub!507
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/issue-502"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Anonymous visitors in OIDC anonymous-read mode browse everything but execute zero writes — every attempted write refuses server-side (uniform 401) and routes to a new log-in interstitial returning to the attempted action.
Backend (docs/go/06_server_http.md §8.6): gate() 401-for-anonymous on AuthWrite/AuthAdmin before flag checks (defect B); ssh-keys explicit anonymous check closing the defect-A leak; apiServe oidc anonymous write-assert middleware; releases/tags requireRole confirmed 401.
Client: headless web/src/lib/writeGate.js + /login-required page + per-affordance wiring (star/watch/fork, New issue/pull, composers, reactions, create forms) + SDK _call noPopupAuth opt-out.
Docs: 06 §8.6, 12_web_ui (§1.2 + §2.3), features/01 §4.1 + Decisions.
Tests: internal/api + internal/server green (-race), coverage api 95.3% / server 98.4%; node 1122/1121 (1 pre-existing live-server smoke fail, also on main); vite+esbuild green. Fixes #502.