A member signing in has no idea what Gitea is, and for anyone this platform is ever sold to it is a competitor's name on their login page. Fourteen strings named it — a button, a logout page, an account-creation notice and eleven error messages — plus Gitea's own sign-in and authorize screens, which every member passes through. Ours are reworded: "el servidor de cuentas" where the thing has to be referred to at all, and nothing where it did not. Gitea's own screens take APP_NAME plus the two footer switches, which are supported settings rather than a patched template. APP_NAME goes in app.ini's unnamed root section, spelled DEFAULT in the environment mapping, so the docs carry a command to confirm it landed — a key written to a section that does not exist is accepted in silence. Comments, docstrings, column names and env vars keep the real name. The code has to stay honest about what it talks to, none of it reaches a browser, and renaming gitea_login would mean a migration for nothing. Two guards added, since this is the kind of thing that creeps back one error message at a time: no template renders the word outside a Jinja comment, and no string literal outside a docstring contains it. Checked against the previous commit, where they catch the one message that had already been missed by hand. Licence: MIT, no attribution-in-UI clause, and we redistribute nothing — the official image runs unmodified with its own LICENSE intact. Gitea ships the "powered by" switch itself. Reasoning recorded in §12. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NizVpJ2dwzCbjCrTLCjeHn
66 lines
3.2 KiB
YAML
66 lines
3.2 KiB
YAML
# Gitea — self-hosted git + OAuth provider for Decap and Woodpecker.
|
|
# Copy this directory to /srv/gitea/ on the server, then: docker compose up -d
|
|
# Web UI is bound to localhost only; Caddy proxies git.vienalatina.com to it.
|
|
|
|
services:
|
|
gitea:
|
|
image: gitea/gitea:1.22
|
|
restart: unless-stopped
|
|
environment:
|
|
- USER_UID=1000
|
|
- USER_GID=1000
|
|
- GITEA__server__DOMAIN=git.vienalatina.com
|
|
- GITEA__server__ROOT_URL=https://git.vienalatina.com/
|
|
- GITEA__server__SSH_DOMAIN=git.vienalatina.com
|
|
- GITEA__service__DISABLE_REGISTRATION=true
|
|
- GITEA__webhook__ALLOWED_HOST_LIST=ci.vienalatina.com
|
|
# Decap is served from vienalatina.com but exchanges its OAuth code for a
|
|
# token by calling git.vienalatina.com from the browser — a cross-origin
|
|
# request. Without this, Gitea returns no Access-Control-Allow-Origin, the
|
|
# browser drops the response, and Decap reports "TypeError: Failed to
|
|
# fetch" right after you authorize, which reads like a Decap bug.
|
|
- GITEA__cors__ENABLED=true
|
|
- GITEA__cors__ALLOW_DOMAIN=https://vienalatina.com
|
|
- GITEA__cors__METHODS=GET,HEAD,POST,PUT,PATCH,DELETE,OPTIONS
|
|
- GITEA__cors__HEADERS=Content-Type,User-Agent,Authorization
|
|
|
|
# Members reach /comunidad/ through Gitea's sign-in and authorize
|
|
# screens, so those are part of the site's journey even for people
|
|
# who never open a repository. DEFAULT_THEME is what anonymous
|
|
# visitors get, which is exactly those two pages.
|
|
# Install the theme first: bash scripts/gitea-theme.sh
|
|
- GITEA__ui__DEFAULT_THEME=vienalatina
|
|
|
|
# The name on those same screens. A member signing in should not be
|
|
# handed off to a product they have never heard of — as far as they are
|
|
# concerned this is still Viena Latina, and the page title, the tab and
|
|
# the heading should say so. APP_NAME lives in app.ini's unnamed root
|
|
# section, which is spelled DEFAULT in the environment mapping.
|
|
#
|
|
# VERIFY IT TOOK: `docker compose exec gitea cat /data/gitea/conf/app.ini
|
|
# | head -5` should show APP_NAME = Viena Latina. A key written to the
|
|
# wrong section is accepted in silence and changes nothing.
|
|
- GITEA__DEFAULT__APP_NAME=Viena Latina
|
|
|
|
# The footer, which otherwise advertises the software and its version on
|
|
# every page. The version is the one with a security argument: it tells a
|
|
# passer-by exactly which advisories to try.
|
|
- GITEA__other__SHOW_FOOTER_POWERED_BY=false
|
|
- GITEA__other__SHOW_FOOTER_VERSION=false
|
|
- GITEA__other__SHOW_FOOTER_TEMPLATE_LOAD_TIME=false
|
|
|
|
# Two tabs on the sign-in page that should not be offered here.
|
|
# OpenID is sign-in with an external identity URL, which nobody in
|
|
# this association will ever use; the register button contradicts
|
|
# DISABLE_REGISTRATION above, which is worse than useless — it invites
|
|
# people to try something the server then refuses.
|
|
- GITEA__openid__ENABLE_OPENID_SIGNIN=false
|
|
- GITEA__openid__ENABLE_OPENID_SIGNUP=false
|
|
- GITEA__service__SHOW_REGISTRATION_BUTTON=false
|
|
volumes:
|
|
- ./data:/data
|
|
- /etc/timezone:/etc/timezone:ro
|
|
- /etc/localtime:/etc/localtime:ro
|
|
ports:
|
|
- "127.0.0.1:3000:3000"
|