From 22f32a46abfec147221b1e40647a888ef50b6fc0 Mon Sep 17 00:00:00 2001 From: sneak Date: Mon, 28 Sep 2026 21:34:57 +0000 Subject: [PATCH] SPEC: gitea branch names with a command after a slash (closes #6) Sixth review of the spec update: the gitea note on branch, tag and file names now also covers names with a listed command right after a `/`, such as `feat/docker-support`, which rule 932260 refuses in the same query parameters. It also says what saving such a branch protection rule looks like: gitea stores it, then returns to the branch settings page with `rule_name` in its address, which gets the sidecar's 403 answer. Model: opus-5-5 --- SPEC.md | 34 +++++++++++++++++++--------------- 1 file changed, 19 insertions(+), 15 deletions(-) diff --git a/SPEC.md b/SPEC.md index 1caa863..218b938 100644 --- a/SPEC.md +++ b/SPEC.md @@ -1172,21 +1172,25 @@ networks: `docker-compose.yml`. - A branch, tag or file name that starts with `docker-`, `python3`, `ansible`, `base64`, `whoami` or another entry on the Core Rule Set's - list of commands (932260), where gitea's own pages send it in a query - parameter that 930120, 932160 and 932260 still check: `refSubUrl`, the - branch or tag of a directory listing, sent when the listing asks for - its entries' last commits in a second request, as it does whenever - gitea takes more than a second to work them out; `name`, when a branch - is deleted or restored on the branches page; `tag`, when a release is - started from a tag; `template`, the file of an issue template, when an - issue is opened from it; and `rule_name`, when a branch protection - rule is opened for editing in the repository's settings. For a branch - named `docker-build`, a directory listing that makes that second - request leaves those last commits out and shows an error, and the - branches page shows an error instead of deleting or restoring the - branch. A release started from such a tag, an issue from such a - template or such a rule opened for editing gets the sidecar's 403 - answer in place of its form. + list of commands (932260), or that has one of these right after a `/`, + such as `feat/docker-support`, `fix/docker-build` or + `renovate/docker-build-push-action-6.x`, where gitea's own pages send + it in a query parameter that 930120, 932160 and 932260 still check: + `refSubUrl`, the branch or tag of a directory listing, sent when the + listing asks for its entries' last commits in a second request, as it + does whenever gitea takes more than a second to work them out; `name`, + when a branch is deleted or restored on the branches page; `tag`, when + a release is started from a tag; `template`, the file of an issue + template, when an issue is opened from it; and `rule_name`, when a + branch protection rule is opened for editing in the repository's + settings or has just been saved. For a branch named `docker-build`, a + directory listing that makes that second request leaves those last + commits out and shows an error, and the branches page shows an error + instead of deleting or restoring the branch. A release started from + such a tag, an issue from such a template or such a rule opened for + editing gets the sidecar's 403 answer in place of its form. Saving + such a rule stores it, but the branch settings page gitea then returns + to gets the sidecar's 403 answer, so the save looks as if it failed. - A path: a file name ending in `~`, or an `.xhtml` file whose path holds a space. - Artifact uploads from `actions/upload-artifact@v3` send the header