From b69e9d6f81847a945f08405dcc2317232c2cf87a Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 18 Sep 2026 14:17:44 +0000 Subject: [PATCH] Let Gitea answer Decap's cross-origin token request MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Decap is served from vienalatina.com and posts its OAuth code to git.vienalatina.com/login/oauth/access_token from the browser. Gitea disables CORS by default, so the browser discarded the response and Decap surfaced it as "TypeError: Failed to fetch" after a successful authorize — the login looks broken at the last step, with nothing wrong on either side individually. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01NizVpJ2dwzCbjCrTLCjeHn --- infra/gitea/docker-compose.yml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/infra/gitea/docker-compose.yml b/infra/gitea/docker-compose.yml index af12bde..1caa404 100644 --- a/infra/gitea/docker-compose.yml +++ b/infra/gitea/docker-compose.yml @@ -14,6 +14,15 @@ services: - GITEA__server__SSH_DOMAIN=git.vienalatina.com - GITEA__service__DISABLE_REGISTRATION=true - GITEA__webhook__ALLOWED_HOST_LIST=ci.vienalatina.com + # Decap is served from vienalatina.com but exchanges its OAuth code for a + # token by calling git.vienalatina.com from the browser — a cross-origin + # request. Without this, Gitea returns no Access-Control-Allow-Origin, the + # browser drops the response, and Decap reports "TypeError: Failed to + # fetch" right after you authorize, which reads like a Decap bug. + - GITEA__cors__ENABLED=true + - GITEA__cors__ALLOW_DOMAIN=https://vienalatina.com + - GITEA__cors__METHODS=GET,HEAD,POST,PUT,PATCH,DELETE,OPTIONS + - GITEA__cors__HEADERS=Content-Type,User-Agent,Authorization volumes: - ./data:/data - /etc/timezone:/etc/timezone:ro