22 lines
1.1 KiB
JavaScript
22 lines
1.1 KiB
JavaScript
import { execFileSync } from "node:child_process";
|
|
|
|
// Inspect the unauthenticated challenge before sending credentials or building images.
|
|
const headers = execFileSync("curl", [
|
|
"--silent", "--show-error", "--max-time", "20",
|
|
"--header", "Cache-Control: no-cache", "--dump-header", "-",
|
|
"--output", process.platform === "win32" ? "NUL" : "/dev/null",
|
|
"https://git.jfritzsche.de/v2/",
|
|
], { encoding: "utf8" });
|
|
const realm = headers.match(/^www-authenticate:\s*Bearer[^\r\n]*realm="([^"]+)"/im)?.[1];
|
|
if (realm !== "https://git.jfritzsche.de/v2/token") {
|
|
throw new Error(
|
|
`Registry advertises an unexpected authentication realm: ${realm ?? "missing"}. ` +
|
|
"Set Gitea [server] ROOT_URL=https://git.jfritzsche.de/ " +
|
|
"(Docker: GITEA__server__ROOT_URL), recreate the Gitea container when changing its environment, " +
|
|
"and check the proxy: in Gitea 1.22.3 forwarded scheme headers override ROOT_URL. " +
|
|
"The trusted proxy must pass X-Forwarded-Proto=https for the public HTTPS request. " +
|
|
"Verify the live /v2/ challenge. No credentials were sent by this check.",
|
|
);
|
|
}
|
|
console.log("Registry HTTPS authentication endpoint verified.");
|