Document the Decap OAuth app as a public PKCE client
Gitea ticks "Confidential Client" by default, which makes it demand a client secret. Decap runs in the browser and authenticates with PKCE, so there is nowhere to keep one — the login then fails after the authorize screen, which reads like a Decap bug rather than a registration mistake. Also spells out step 9 as commands, notes that the Client ID is published in the site's JavaScript by design (so committing it is fine, but the placeholder is what belongs in a resold copy), and records the two failure modes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NizVpJ2dwzCbjCrTLCjeHn
This commit is contained in:
parent
b96920c6bc
commit
6890ff4153
@ -146,8 +146,15 @@ Then create the two OAuth apps and the bot user, all in the Gitea web UI:
|
|||||||
- Save the **Client ID** and **Client Secret** — needed in step 7.
|
- Save the **Client ID** and **Client Secret** — needed in step 7.
|
||||||
2. **Decap OAuth app:** same screen, second application
|
2. **Decap OAuth app:** same screen, second application
|
||||||
- Name: `decap-cms`
|
- Name: `decap-cms`
|
||||||
- Redirect URI: `https://vienalatina.com/admin/`
|
- Redirect URI: `https://vienalatina.com/admin/` (exactly, trailing slash
|
||||||
|
included — Gitea matches it literally)
|
||||||
|
- **Untick "Confidential Client".** Decap runs in the browser and
|
||||||
|
authenticates with PKCE; a confidential app makes Gitea demand a client
|
||||||
|
secret that a browser cannot keep, and the login fails *after* you
|
||||||
|
authorize, which makes it look like a Decap bug.
|
||||||
- Save the **Client ID** — it goes into `static/admin/config.yml` (step 9).
|
- Save the **Client ID** — it goes into `static/admin/config.yml` (step 9).
|
||||||
|
There is no secret to save, and the Client ID is not one either: it is
|
||||||
|
published in the site's JavaScript by design.
|
||||||
3. **Translations bot:** Site Administration → Identity & Access →
|
3. **Translations bot:** Site Administration → Identity & Access →
|
||||||
User Accounts → *Create User Account*
|
User Accounts → *Create User Account*
|
||||||
- Username: `translations`, email: `translations@vienalatina.com`,
|
- Username: `translations`, email: `translations@vienalatina.com`,
|
||||||
@ -225,6 +232,21 @@ On your working copy: edit `static/admin/config.yml`, replace
|
|||||||
step 6.2, commit, push to Gitea. (You can't log into `/admin` until the main
|
step 6.2, commit, push to Gitea. (You can't log into `/admin` until the main
|
||||||
domain is live — that's expected.)
|
domain is live — that's expected.)
|
||||||
|
|
||||||
|
```sh
|
||||||
|
cd ~/vienalatina
|
||||||
|
sed -i 's/REPLACE_WITH_GITEA_OAUTH_CLIENT_ID/<client id>/' static/admin/config.yml
|
||||||
|
grep app_id static/admin/config.yml
|
||||||
|
git commit -am "Wire Decap to the Gitea OAuth app" && git push gitea main
|
||||||
|
```
|
||||||
|
|
||||||
|
This value is per-deployment: the placeholder is what belongs in the repo, so
|
||||||
|
leave it in place in any copy of this platform that is not this server.
|
||||||
|
|
||||||
|
If `/admin/` still shows *Client ID not registered* afterwards, the page is
|
||||||
|
serving a cached `config.yml` — hard-reload it. If it fails *after* the Gitea
|
||||||
|
authorize screen instead, the app was created as a confidential client; delete
|
||||||
|
it and recreate it with that box unticked.
|
||||||
|
|
||||||
## 10. Test the translation loop end-to-end
|
## 10. Test the translation loop end-to-end
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user