From 6890ff4153e709c1d57791f633403e44908f7304 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 18 Sep 2026 13:57:17 +0000 Subject: [PATCH] Document the Decap OAuth app as a public PKCE client MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Gitea ticks "Confidential Client" by default, which makes it demand a client secret. Decap runs in the browser and authenticates with PKCE, so there is nowhere to keep one — the login then fails after the authorize screen, which reads like a Decap bug rather than a registration mistake. Also spells out step 9 as commands, notes that the Client ID is published in the site's JavaScript by design (so committing it is fine, but the placeholder is what belongs in a resold copy), and records the two failure modes. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01NizVpJ2dwzCbjCrTLCjeHn --- docs/server-setup.md | 24 +++++++++++++++++++++++- 1 file changed, 23 insertions(+), 1 deletion(-) diff --git a/docs/server-setup.md b/docs/server-setup.md index e47358a..d457fd5 100644 --- a/docs/server-setup.md +++ b/docs/server-setup.md @@ -146,8 +146,15 @@ Then create the two OAuth apps and the bot user, all in the Gitea web UI: - Save the **Client ID** and **Client Secret** — needed in step 7. 2. **Decap OAuth app:** same screen, second application - Name: `decap-cms` - - Redirect URI: `https://vienalatina.com/admin/` + - Redirect URI: `https://vienalatina.com/admin/` (exactly, trailing slash + included — Gitea matches it literally) + - **Untick "Confidential Client".** Decap runs in the browser and + authenticates with PKCE; a confidential app makes Gitea demand a client + secret that a browser cannot keep, and the login fails *after* you + authorize, which makes it look like a Decap bug. - Save the **Client ID** — it goes into `static/admin/config.yml` (step 9). + There is no secret to save, and the Client ID is not one either: it is + published in the site's JavaScript by design. 3. **Translations bot:** Site Administration → Identity & Access → User Accounts → *Create User Account* - Username: `translations`, email: `translations@vienalatina.com`, @@ -225,6 +232,21 @@ On your working copy: edit `static/admin/config.yml`, replace step 6.2, commit, push to Gitea. (You can't log into `/admin` until the main domain is live — that's expected.) +```sh +cd ~/vienalatina +sed -i 's/REPLACE_WITH_GITEA_OAUTH_CLIENT_ID//' static/admin/config.yml +grep app_id static/admin/config.yml +git commit -am "Wire Decap to the Gitea OAuth app" && git push gitea main +``` + +This value is per-deployment: the placeholder is what belongs in the repo, so +leave it in place in any copy of this platform that is not this server. + +If `/admin/` still shows *Client ID not registered* afterwards, the page is +serving a cached `config.yml` — hard-reload it. If it fails *after* the Gitea +authorize screen instead, the app was created as a confidential client; delete +it and recreate it with that box unticked. + ## 10. Test the translation loop end-to-end ```sh