SPEC: gitea branch names with a command after a slash (closes #6)

Sixth review of the spec update: the gitea note on branch, tag and
file names now also covers names with a listed command right after a
`/`, such as `feat/docker-support`, which rule 932260 refuses in the
same query parameters. It also says what saving such a branch
protection rule looks like: gitea stores it, then returns to the
branch settings page with `rule_name` in its address, which gets the
sidecar's 403 answer.

Model: opus-5-5
This commit is contained in:
2026-09-28 21:34:57 +00:00
parent 8b3aba84b2
commit 22f32a46ab
+19 -15
View File
@@ -1172,21 +1172,25 @@ networks:
`docker-compose.yml`.
- A branch, tag or file name that starts with `docker-`, `python3`,
`ansible`, `base64`, `whoami` or another entry on the Core Rule Set's
list of commands (932260), where gitea's own pages send it in a query
parameter that 930120, 932160 and 932260 still check: `refSubUrl`, the
branch or tag of a directory listing, sent when the listing asks for
its entries' last commits in a second request, as it does whenever
gitea takes more than a second to work them out; `name`, when a branch
is deleted or restored on the branches page; `tag`, when a release is
started from a tag; `template`, the file of an issue template, when an
issue is opened from it; and `rule_name`, when a branch protection
rule is opened for editing in the repository's settings. For a branch
named `docker-build`, a directory listing that makes that second
request leaves those last commits out and shows an error, and the
branches page shows an error instead of deleting or restoring the
branch. A release started from such a tag, an issue from such a
template or such a rule opened for editing gets the sidecar's 403
answer in place of its form.
list of commands (932260), or that has one of these right after a `/`,
such as `feat/docker-support`, `fix/docker-build` or
`renovate/docker-build-push-action-6.x`, where gitea's own pages send
it in a query parameter that 930120, 932160 and 932260 still check:
`refSubUrl`, the branch or tag of a directory listing, sent when the
listing asks for its entries' last commits in a second request, as it
does whenever gitea takes more than a second to work them out; `name`,
when a branch is deleted or restored on the branches page; `tag`, when
a release is started from a tag; `template`, the file of an issue
template, when an issue is opened from it; and `rule_name`, when a
branch protection rule is opened for editing in the repository's
settings or has just been saved. For a branch named `docker-build`, a
directory listing that makes that second request leaves those last
commits out and shows an error, and the branches page shows an error
instead of deleting or restoring the branch. A release started from
such a tag, an issue from such a template or such a rule opened for
editing gets the sidecar's 403 answer in place of its form. Saving
such a rule stores it, but the branch settings page gitea then returns
to gets the sidecar's 403 answer, so the save looks as if it failed.
- A path: a file name ending in `~`, or an `.xhtml` file whose path
holds a space.
- Artifact uploads from `actions/upload-artifact@v3` send the header