vienalatina/apps/board
Claude ea17bf3273
Give Gitea a deploy path, and invitations a second chance
Two findings from one screenshot of a dead forgot-password page.

The page is Gitea's own, and it will always say recovery is disabled:
the SMTP details are the members area's, and Gitea is a different
container with no mailer and no need for one. But every member reaches
Gitea's sign-in form on the way in, and that form links to it — so the
broken route is the one they find first. The theme now hides the link.
Ours, which works, is /comunidad/recuperar.

The footer on that page still advertised the software and its version,
which proves the settings added days ago never reached the server.
/srv/gitea/docker-compose.yml is a copy and nothing ever synced it:
deploy-board.sh syncs the board's compose file, and the Gitea directory
has been hand-made since setup. CORS, the theme, OpenID, the register
button, the footer — committed, documented, never applied. The file
stays valid and the container stays healthy, which is why nobody
noticed. scripts/deploy-gitea.sh syncs it, restarts, and then reads the
settings back out of the running container and prints them, because
this session has lost three separate afternoons to settings that were
accepted somewhere and read by nobody.

Separately: an invitation was only ever issued when the app created the
account. Make the account by hand, add the member with the box
unticked, and no invitation exists and none can be made — which is
exactly how somebody ended up with an account nobody knew the password
to. Miembros now has "Enviar invitación" on any active member with an
address, for that case and for a failed send, an expired link or a
corrected address. Issuing a new token voids the old one, so a
forwarded link stops working. Refused before a token is issued when
there is no address, since otherwise a working invitation would be
spent on one that cannot be delivered.

183 tests.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NizVpJ2dwzCbjCrTLCjeHn
2026-09-28 15:15:35 +00:00
..
static Let members post pictures, and back them up 2026-09-28 09:02:18 +00:00
templates Give Gitea a deploy path, and invitations a second chance 2026-09-28 15:15:35 +00:00
tests Give Gitea a deploy path, and invitations a second chance 2026-09-28 15:15:35 +00:00
__init__.py Add a members area: roles and an internal board 2026-09-22 10:57:18 +00:00
app.py Let members post pictures, and back them up 2026-09-28 09:02:18 +00:00
auth.py Stop showing members the name of the software behind the login 2026-09-25 19:30:06 +00:00
board.py Let members post pictures, and back them up 2026-09-28 09:02:18 +00:00
content.py Let members post pictures, and back them up 2026-09-28 09:02:18 +00:00
db.py Add a members area: roles and an internal board 2026-09-22 10:57:18 +00:00
gitea.py Stop showing members the name of the software behind the login 2026-09-25 19:30:06 +00:00
invites.py Let members get a password of their own 2026-09-25 17:49:39 +00:00
mail.py Let members get a password of their own 2026-09-25 17:49:39 +00:00
members.py Give Gitea a deploy path, and invitations a second chance 2026-09-28 15:15:35 +00:00
render.py Add a members area: roles and an internal board 2026-09-22 10:57:18 +00:00
requirements.txt Write the site from the members area instead of Decap 2026-09-25 15:07:31 +00:00
schema.sql Let members post pictures, and back them up 2026-09-28 09:02:18 +00:00
security.py Add a members area: roles and an internal board 2026-09-22 10:57:18 +00:00
tokens.py Write the site from the members area instead of Decap 2026-09-25 15:07:31 +00:00
uploads.py Let members post pictures, and back them up 2026-09-28 09:02:18 +00:00
wsgi.py Add a members area: roles and an internal board 2026-09-22 10:57:18 +00:00