Conversation
Manual validation noteIn addition to the automated test suite, which is currently passing, I have The following scenarios were verified:
The positive end-to-end test also verified the issued token using only the This is mainly a note for tracking the current Draft validation state; I still |
|
Make sure your agent has read AGENTS.md and followed it exactly. Based on this long PR description, I see that it didn't read it. Please re-review the whole work under the AGENTS.md constraints. |
Sorry! I’ve now amended the pull request description in line with the guidelines in AGENTS.md, and I’ve added the screenshots I’d already prepared. I’ll check the entire change once more against the guidelines in AGENTS.md before removing the pull request from draft status. |
|
Thanks, yes that's a more managable size now :) |
|
While reviewing/testing this, I noticed an unrelated existing issue in the OAuth2 JWT signing-key setup: auto-generated ECDSA keys always use P-256, even when I don't think this belongs in this PR. Would you prefer a separate issue for it? I can open one later and look at it independently. |
|
I've now completed my own review of the implementation and tests. The remaining piece is documentation, which I'll add separately. In the meantime, feel free to take a look already — feedback and comments are very welcome. |
|
Also verified that the Gitea Actions runner masks |
47a494c to
de5952f
Compare
8d8ce04 to
a54eaa8
Compare
Derive token permissions and identity claims from canonical server state, persist authoritative workflow paths, and cover capability access and signing behavior. Assisted-by: OpenCode:gpt-5.6-sol
Legacy schedules can create runs without an authoritative workflow path. Keep OIDC unavailable for these runs, as before OIDC support was introduced, until the schedule is rebuilt. Assisted-by: OpenCode:gpt-5.6-sol
Fail OIDC token issuance when reusable workflow provenance cannot be resolved or does not include the resolved workflow commit. Assisted-by: OpenCode:gpt-5.6-sol
Treat the unsupported id-token read mode as none while preserving write-all and explicit id-token write behavior. Assisted-by: OpenCode:gpt-5.6-sol
Avoid evaluating OIDC eligibility while the provider is unavailable so disabled OIDC cannot interfere with normal task context generation. Assisted-by: OpenCode:gpt-5.6-sol
Cover workflow path persistence for scheduled runs and scoped workflow dispatches. Assisted-by: OpenCode:gpt-5.6-terra
Verify that cyclic reusable workflow parent chains are rejected while computing effective token permissions. Assisted-by: OpenCode:gpt-5.6-terra
Avoid resolving OIDC provenance and effective permissions for jobs that did not explicitly request id-token write access. Assisted-by: OpenCode:gpt-5.6-luna
Verify that reusable workflow callers restrict both repository unit permissions and OIDC token permissions. Assisted-by: OpenCode:gpt-5.6-luna
Keep invalid authorization and task state failures as 401 responses while surfacing unexpected task lookup failures as logged internal server errors. Assisted-by: OpenCode:gpt-5.6-luna
Reject token issuance when the root workflow source commit or reference is missing, and cover root, reusable, scoped, and signing-key provenance cases. Assisted-by: OpenCode:gpt-5.6-terra
Verify the discovery-to-JWKS chain and require the expected bearer challenge for rejected OIDC token requests. Assisted-by: OpenCode:gpt-5.6-luna
f77c47b to
f0728b3
Compare
Follow upstream commit 32728fc and avoid reintroducing github.com/google/uuid as a direct dependency.
f0728b3 to
978b01d
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Cancelling-task issuance, optional key initialization, and migrated schedules currently have lifecycle and reliability defects.
Review effort: Balanced
Findings: 1
Open (4)
What changed in this PR
Adds OIDC workload identities to Gitea Actions, including permission enforcement, provenance claims, token endpoints, configuration UI, and tests.
Changes:
- Adds OIDC discovery, JWKS, and token issuance endpoints.
- Tracks workflow provenance and enforces effective
id-tokenpermissions. - Adds configuration UI, migration, and automated coverage.
| File | Description |
|---|---|
| tests/integration/actions_trigger_test.go | Verifies triggered-run workflow paths. |
| tests/integration/actions_scoped_workflow_test.go | Verifies scoped workflow paths. |
| tests/integration/actions_schedule_test.go | Verifies scheduled workflow paths. |
| tests/integration/actions_oidc_test.go | Tests the complete OIDC flow. |
| tests/integration/actions_concurrency_test.go | Checks scheduled concurrency provenance. |
| templates/shared/actions/permissions_table.tmpl | Adds the ID-token permission control. |
| services/actions/workflow.go | Records dispatched workflow paths. |
| services/actions/task.go | Exposes OIDC request context to runners. |
| services/actions/schedule_tasks.go | Propagates scheduled workflow paths. |
| services/actions/permission_parser.go | Parses id-token permissions. |
| services/actions/permission_parser_test.go | Tests permission parsing. |
| services/actions/oidc.go | Implements OIDC authorization and claims. |
| services/actions/oidc_test.go | Tests OIDC services and claims. |
| services/actions/notifier_helper.go | Records detected workflow paths. |
| services/actions/init.go | Initializes OIDC signing support. |
| services/actions/auth.go | Restricts runtime JWTs to HS256. |
| services/actions/auth_test.go | Tests JWT algorithm rejection. |
| routers/web/shared/actions/general.go | Parses ID-token settings. |
| routers/api/actions/oidc.go | Implements OIDC HTTP handlers. |
| routers/api/actions/actions.go | Registers OIDC routes. |
| options/locale/locale_en-US.json | Adds OIDC permission labels. |
| modules/actions/workflows.go | Captures detected workflow paths. |
| modules/actions/scoped_workflows.go | Captures scoped workflow paths. |
| models/repo/repo_unit_test.go | Tests ID-token defaults and limits. |
| models/repo/repo_unit_actions.go | Extends token permission storage. |
| models/actions/utils.go | Copies schedule workflow provenance. |
| models/actions/token_permissions.go | Clamps reusable-workflow permissions. |
| models/actions/token_permissions_test.go | Tests effective OIDC permissions. |
| models/actions/schedule.go | Stores scheduled workflow paths. |
| models/actions/run.go | Stores run workflow paths. |
| models/actions/config.go | Adds owner-level OIDC limits. |
| modelmigration/v28/v353.go | Adds workflow-path columns. |
| modelmigration/v28/v353_test.go | Tests the schema migration. |
| modelmigration/migrations.go | Registers migration 353. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Assisted-by: Claude Code:claude-opus-5-5 # Conflicts: # modelmigration/migrations.go # modelmigration/v28/v353.go # modelmigration/v28/v353_test.go # modules/actions/workflows.go
Tokens now follow GitHub's format so existing clients and trust policies carry over: the immutable subject, a single string audience, the workflow name and fully qualified reusable workflow refs recorded when the workflow is loaded, so a same-named tag can't pose as a branch. A dedicated signing key replaces the OAuth2 provider key, which could end startup when missing, and a separate request token keeps the runtime token that runners also send to cache servers from minting OIDC tokens. Cancelling tasks can still request one for cleanup. The workflow directory is derived from the recorded commit instead of a stored path, which migrated schedules lacked, and the reusable workflow permission walk is dropped since callers already clamp their children when they are expanded. Assisted-by: Claude Code:claude-opus-5-5
* origin/main: fix: copy new access token to clipboard (go-gitea#39496)
release/v28 ends at migration 355, so 356 starts the next version. Assisted-by: Claude Code:claude-opus-5-5
|
Reworked this on top of main, with GitHub compatibility as the priority:
The docs in https://gitea.com/gitea/docs/pulls/526 are updated to match. Written by Claude Code (claude-opus-5-5) |
|
Cut out about 1k lines from the PR while fixing the issues above, migration is moved to v29, pr description updated and shortened. |


Adds OpenID Connect workload identity to Gitea Actions: jobs declaring
id-token: writecan request short-lived tokens to authenticate to cloud providers and other services without stored secrets. Tokens follow GitHub's format, so clients like@actions/coreand existing trust policies carry over./api/actions/oidcwith discovery and JWKS, signed with a dedicated RS256 keyworkflow_ref,job_workflow_refand the immutablerepo:owner@id/repo@id:ref:...subjectid-token: writeorwrite-allgrant it, default permissions and fork pull requests never get it, owner and repository maximum permissions can disable itgithub.ref_typeisbranchfor pull request runs, like on GitHubFixes #26383
Fixes #33681
Docs: https://gitea.com/gitea/docs/pulls/526
Before:
After:
Assisted-by: ChatGPT:gpt-5.6-sol, Claude Code:claude-opus-5-5