The JSON API (/api/v1/*) currently only supports cookie-based session auth. For programmatic/CI use, it needs bearer token authentication.
Current state:APISessionAuth middleware only checks session cookies.
Needed for 1.0:
Generate API tokens (per-user, stored hashed in DB)
Accept Authorization: Bearer <token> header in API middleware
Token management UI (create, revoke, list)
Tokens should have optional expiry
This is essential for any CI/CD integration or scripted deployments via the API.
The JSON API (`/api/v1/*`) currently only supports cookie-based session auth. For programmatic/CI use, it needs bearer token authentication.
**Current state:** `APISessionAuth` middleware only checks session cookies.
**Needed for 1.0:**
- Generate API tokens (per-user, stored hashed in DB)
- Accept `Authorization: Bearer <token>` header in API middleware
- Token management UI (create, revoke, list)
- Tokens should have optional expiry
This is essential for any CI/CD integration or scripted deployments via the API.
sneak
added this to the 1.5 milestone 2026-02-19 22:43:34 +01:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The JSON API (
/api/v1/*) currently only supports cookie-based session auth. For programmatic/CI use, it needs bearer token authentication.Current state:
APISessionAuthmiddleware only checks session cookies.Needed for 1.0:
Authorization: Bearer <token>header in API middlewareThis is essential for any CI/CD integration or scripted deployments via the API.
WONTFIX