Can't get the Java API generateRepo Function #7708

Closed
opened 2025-11-02 07:34:14 -06:00 by GiteaMirror · 3 comments
Owner

Originally created by @vw98075 on GitHub (Aug 18, 2021).

  • Gitea version (or commit ref): 1.15.0+rc3-10-g25437672b as well as a previous version
  • Git version: Go1.16.5
  • Operating system: MacOS

Local build

  • Database (use [x]):
    • [ x] PostgreSQL
    • MySQL
    • MSSQL
    • SQLite
  • Can you reproduce the bug at https://try.gitea.io:
    • Yes (provide example URL)
    • No
  • Log gist:
2021/08/18 16:40:50 Started GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=nW0EacrKHDgc759qF-DtUrECeWb9F3r-s0TYmJoqSf4%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=RklWldnT8ICsWZnzw8YIHW-YgYZLD5oGzwK065XuUm0 for [::1]:53035
2021/08/18 16:40:50 Completed GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=nW0EacrKHDgc759qF-DtUrECeWb9F3r-s0TYmJoqSf4%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=RklWldnT8ICsWZnzw8YIHW-YgYZLD5oGzwK065XuUm0 302 Found in 399.91µs
2021/08/18 16:40:50 Started GET /user/login for [::1]:53035
2021/08/18 16:40:50 Completed GET /user/login 200 OK in 2.780976ms
2021/08/18 16:40:52 Started POST /user/login for [::1]:53035
2021/08/18 16:40:53 Completed POST /user/login 302 Found in 18.950178ms
2021/08/18 16:40:53 Started GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=nW0EacrKHDgc759qF-DtUrECeWb9F3r-s0TYmJoqSf4%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=RklWldnT8ICsWZnzw8YIHW-YgYZLD5oGzwK065XuUm0 for [::1]:53035
2021/08/18 16:40:53 Completed GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=nW0EacrKHDgc759qF-DtUrECeWb9F3r-s0TYmJoqSf4%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=RklWldnT8ICsWZnzw8YIHW-YgYZLD5oGzwK065XuUm0 302 Found in 4.041186ms
2021/08/18 16:40:53 Started POST /login/oauth/access_token for 127.0.0.1:53056
2021/08/18 16:40:53 Completed POST /login/oauth/access_token 200 OK in 91.736432ms
2021/08/18 16:40:53 Started GET /login/oauth/keys for 127.0.0.1:53056
2021/08/18 16:40:53 Completed GET /login/oauth/keys 200 OK in 226.173µs
2021/08/18 16:40:53 Started GET /login/oauth/userinfo for 127.0.0.1:53056
2021/08/18 16:40:53 Completed GET /login/oauth/userinfo 200 OK in 1.249603ms
2021/08/18 16:41:02 Started POST /api/v1/repos/gitea-admin/java-code-templete/generate?access_token=Token%20eyJhbGciOiJSUzI1NiIsImtpZCI6Ikd5OW0ybUxRVFNvYldYMGRYWWRMRzN6SFo2Vi1TQ28zcnJ0MzhwUG9IUmciLCJ0eXAiOiJKV1QifQ.eyJnbnQiOjEsInR0IjowLCJleHAiOjE2MjkzMzM2NTMsImlhdCI6MTYyOTMzMDA1M30.koMiQefEBThIXoqhDdEPbomEhNtFzUX7sT2FtAolwYt4kdPtVMlMzU6Uz80NGNkD7qlRksP2lh48ZK0FeC6cNDdHqkydXFZC09cks4Ldlq9vCbf-kfkQykh9dLzP4Cn8ElZp6bBPyiuWnuoO3OV64UMdT8ZkIE939ivw8m8kL0U4UkmILggoHCPwX42YDKKa7j6_BH8YECCptd4NYUur8hwolbVApbUYx_o0A-DjsU_bl6S6YrmgpAiJIVEEyvVH-3ubPQYs8R9KeDc_8L4H3KpXTi70WTCnlE2AtApuFiOYpdIjmvOv_bhd5G1f208kEbxYui5TpWXUbjPkaLXay16hY5dsatLLMt_q8QvN4_aj0NkbSKsbwRYwHUm8Y0Mr_GJVXsCCi9KSKrDfWDphGArCJAYPd31N3m0or2PgcQ-qazJHctcin58OkULPgX6uKGaayo8eMDsJbpMg_h9F8YM6A5fz48oRM7BxM8F88khhnziUniRwwjszdTVR3hm7-FvbvZatVAU-SlGUsl7c8TBqzpGbFIazeQO7kBQYH7hrIRj-2r80kU_-t_WjUd8FZNgO-AudeB55MhEr6b__tZyNO_5ZjuEBDfQJwf-6rTQ5_3DPxH43kWY9t3WBacZXIHvFxNt3ERMuZiHvtPsZ91PQHxvcJW4NmO6K7BIqxKo for 127.0.0.1:53152
2021/08/18 16:41:02 Completed POST /api/v1/repos/gitea-admin/java-code-templete/generate?access_token=Token%20eyJhbGciOiJSUzI1NiIsImtpZCI6Ikd5OW0ybUxRVFNvYldYMGRYWWRMRzN6SFo2Vi1TQ28zcnJ0MzhwUG9IUmciLCJ0eXAiOiJKV1QifQ.eyJnbnQiOjEsInR0IjowLCJleHAiOjE2MjkzMzM2NTMsImlhdCI6MTYyOTMzMDA1M30.koMiQefEBThIXoqhDdEPbomEhNtFzUX7sT2FtAolwYt4kdPtVMlMzU6Uz80NGNkD7qlRksP2lh48ZK0FeC6cNDdHqkydXFZC09cks4Ldlq9vCbf-kfkQykh9dLzP4Cn8ElZp6bBPyiuWnuoO3OV64UMdT8ZkIE939ivw8m8kL0U4UkmILggoHCPwX42YDKKa7j6_BH8YECCptd4NYUur8hwolbVApbUYx_o0A-DjsU_bl6S6YrmgpAiJIVEEyvVH-3ubPQYs8R9KeDc_8L4H3KpXTi70WTCnlE2AtApuFiOYpdIjmvOv_bhd5G1f208kEbxYui5TpWXUbjPkaLXay16hY5dsatLLMt_q8QvN4_aj0NkbSKsbwRYwHUm8Y0Mr_GJVXsCCi9KSKrDfWDphGArCJAYPd31N3m0or2PgcQ-qazJHctcin58OkULPgX6uKGaayo8eMDsJbpMg_h9F8YM6A5fz48oRM7BxM8F88khhnziUniRwwjszdTVR3hm7-FvbvZatVAU-SlGUsl7c8TBqzpGbFIazeQO7kBQYH7hrIRj-2r80kU_-t_WjUd8FZNgO-AudeB55MhEr6b__tZyNO_5ZjuEBDfQJwf-6rTQ5_3DPxH43kWY9t3WBacZXIHvFxNt3ERMuZiHvtPsZ91PQHxvcJW4NmO6K7BIqxKo 401 Unauthorized in 2.26503ms
2021/08/18 16:51:08 Started GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=VZSxpNjwFxnyiQAmCcakOg-3lfiAtU8vgRTTQJCV42Q%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=sMUUvQmd_1kB_oN0rm35Hj8dyUuM6DGgEQBBuOsBdwY for [::1]:56323
2021/08/18 16:51:08 Completed GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=VZSxpNjwFxnyiQAmCcakOg-3lfiAtU8vgRTTQJCV42Q%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=sMUUvQmd_1kB_oN0rm35Hj8dyUuM6DGgEQBBuOsBdwY 302 Found in 217.028µs
2021/08/18 16:51:08 Started GET /user/login for [::1]:56323
2021/08/18 16:51:08 Completed GET /user/login 200 OK in 1.873134ms
2021/08/18 16:51:10 Started POST /user/login for [::1]:56323
2021/08/18 16:51:10 Completed POST /user/login 302 Found in 20.930799ms
2021/08/18 16:51:10 Started GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=VZSxpNjwFxnyiQAmCcakOg-3lfiAtU8vgRTTQJCV42Q%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=sMUUvQmd_1kB_oN0rm35Hj8dyUuM6DGgEQBBuOsBdwY for [::1]:56323
2021/08/18 16:51:10 Completed GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=VZSxpNjwFxnyiQAmCcakOg-3lfiAtU8vgRTTQJCV42Q%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=sMUUvQmd_1kB_oN0rm35Hj8dyUuM6DGgEQBBuOsBdwY 302 Found in 3.536243ms
2021/08/18 16:51:10 Started POST /login/oauth/access_token for 127.0.0.1:56366
2021/08/18 16:51:10 Completed POST /login/oauth/access_token 200 OK in 90.175249ms
2021/08/18 16:51:10 Started GET /login/oauth/keys for 127.0.0.1:56366
2021/08/18 16:51:10 Completed GET /login/oauth/keys 200 OK in 196.868µs
2021/08/18 16:51:10 Started GET /login/oauth/userinfo for 127.0.0.1:56366
2021/08/18 16:51:10 Completed GET /login/oauth/userinfo 200 OK in 1.760741ms
2021/08/18 16:52:02 Started POST /api/v1/repos/gitea-admin/java-code-templete/generate?sudo=Token%20eyJhbGciOiJSUzI1NiIsImtpZCI6Ikd5OW0ybUxRVFNvYldYMGRYWWRMRzN6SFo2Vi1TQ28zcnJ0MzhwUG9IUmciLCJ0eXAiOiJKV1QifQ.eyJnbnQiOjEsInR0IjowLCJleHAiOjE2MjkzMzQyNzAsImlhdCI6MTYyOTMzMDY3MH0.G-nBxJ6k9j1OJLhga93K21PXljhCZQfyIVjNH_N4CLpzJUVf_82M9OOIDWCm2rmkshsDO42SJaCB2Fj_2KdNaIOBZFEKy94zfLMl9N3CBYlUqoGwJT9RKXgMR950tepfyHd0q0N-wE7FZiEtPs1aYXsRFsU1po-yAdx0YNVSUFEJOZEQjiS0Mo6E82GeeTiTZC5otGjG3HIuMK8s5qV86BDFcDI9obiued24zZKXDbWdshovWy2edM-i9fPqJazqvsnJPnUTLprsoEs9DubtPeE3UL3WXQr6LAPFDzlltITv1ljM7vcwo_geEBcVit4aB2bx6fxGkWgLqoUYS8xPhu0QWaCFN-MW8BGU0aOFzziFj0El8rRvh9jAzEIJIvU6nTTsY7hd3AFfVRevPCCI8bDpq5ok0rLgD-_kCsFz9jCjK6R5YyGSzFaxM5BRkXiY9n-T8-fS6kiJMvE_5wo4VdKqQZn8XckIUNcWT4ep_lXpF6CLLZcfnPrVVh-EQsp46LF0yqGodU6Isv-y3eDA2vFU38VxfvBKhQ2TQGs43jwAe9aEqAQkrKo1rNJPTnA2ySgFxAk8RxBXKxmHASmwt5Qtdf6jKik1AcbUwAapKLeBNlZLwQ444WmmgjM4WC-sQObLvcq97ezPV8ymUOGYm4zk-RbXLH9kVUKijyffu0A for 127.0.0.1:56679
2021/08/18 16:52:02 Completed POST /api/v1/repos/gitea-admin/java-code-templete/generate?sudo=Token%20eyJhbGciOiJSUzI1NiIsImtpZCI6Ikd5OW0ybUxRVFNvYldYMGRYWWRMRzN6SFo2Vi1TQ28zcnJ0MzhwUG9IUmciLCJ0eXAiOiJKV1QifQ.eyJnbnQiOjEsInR0IjowLCJleHAiOjE2MjkzMzQyNzAsImlhdCI6MTYyOTMzMDY3MH0.G-nBxJ6k9j1OJLhga93K21PXljhCZQfyIVjNH_N4CLpzJUVf_82M9OOIDWCm2rmkshsDO42SJaCB2Fj_2KdNaIOBZFEKy94zfLMl9N3CBYlUqoGwJT9RKXgMR950tepfyHd0q0N-wE7FZiEtPs1aYXsRFsU1po-yAdx0YNVSUFEJOZEQjiS0Mo6E82GeeTiTZC5otGjG3HIuMK8s5qV86BDFcDI9obiued24zZKXDbWdshovWy2edM-i9fPqJazqvsnJPnUTLprsoEs9DubtPeE3UL3WXQr6LAPFDzlltITv1ljM7vcwo_geEBcVit4aB2bx6fxGkWgLqoUYS8xPhu0QWaCFN-MW8BGU0aOFzziFj0El8rRvh9jAzEIJIvU6nTTsY7hd3AFfVRevPCCI8bDpq5ok0rLgD-_kCsFz9jCjK6R5YyGSzFaxM5BRkXiY9n-T8-fS6kiJMvE_5wo4VdKqQZn8XckIUNcWT4ep_lXpF6CLLZcfnPrVVh-EQsp46LF0yqGodU6Isv-y3eDA2vFU38VxfvBKhQ2TQGs43jwAe9aEqAQkrKo1rNJPTnA2ySgFxAk8RxBXKxmHASmwt5Qtdf6jKik1AcbUwAapKLeBNlZLwQ444WmmgjM4WC-sQObLvcq97ezPV8ymUOGYm4zk-RbXLH9kVUKijyffu0A 403 Forbidden in 219.906µs

Description

A Java code consumes the API:

  private ResponseEntity<?> generateRepo(String templateOwner, String templateRepo, io.gitea.model.GenerateRepoOption body, String tokenValue){
        
        ApiClient client = Configuration.getDefaultApiClient();
        client.setBasePath("http://localhost:3000/api/v1");

        // Configure API key authorization: SudoParam
        ApiKeyAuth SudoParam = (ApiKeyAuth) client.getAuthentication("AccessToken");//getAuthentication("SudoParam");  // Unauthorized vs Forbidden
        SudoParam.setApiKey(tokenValue);
        // Uncomment the following line to set a prefix for the API key, e.g. "Token" (defaults to null)
        SudoParam.setApiKeyPrefix("Token");

        RepositoryApi apiInstance = new RepositoryApi();
        try {
            io.gitea.model.Repository result = apiInstance.generateRepo(templateOwner, templateRepo, body);
            return new ResponseEntity<io.gitea.model.Repository>(result, HttpStatus.CREATED);
        } catch (ApiException e) {
            String message = e.getMessage();
            if(message.contains("403")){
                return new ResponseEntity<>(message, HttpStatus.FORBIDDEN);
            }
            if(message.contains("404")){
                return new ResponseEntity<>(message, HttpStatus.NOT_FOUND);
            }
            if(message.contains("409")){
                return new ResponseEntity<>(message, HttpStatus.CONFLICT);
            }
            if(message.contains("422")){
                return new ResponseEntity<>(message, HttpStatus.UNPROCESSABLE_ENTITY);
            }
            return new ResponseEntity<>(message, HttpStatus.INTERNAL_SERVER_ERROR);
        }
    }

The outcome of the above code will be "Unauthorized". And it will be "Forbidden" if replacing the getAuthentication("AccessToken") with getAuthentication("SudoParam"). The first error is normal, a correct behaviour while the second isn't.

The access token is obtained with an OAuth login of an admin user account.
...

Screenshots

Originally created by @vw98075 on GitHub (Aug 18, 2021). <!-- NOTE: If your issue is a security concern, please send an email to security@gitea.io instead of opening a public issue --> <!-- 1. Please speak English, this is the language all maintainers can speak and write. 2. Please ask questions or configuration/deploy problems on our Discord server (https://discord.gg/gitea) or forum (https://discourse.gitea.io). 3. Please take a moment to check that your issue doesn't already exist. 4. Make sure it's not mentioned in the FAQ (https://docs.gitea.io/en-us/faq) 5. Please give all relevant information below for bug reports, because incomplete details will be handled as an invalid report. --> - Gitea version (or commit ref): 1.15.0+rc3-10-g25437672b as well as a previous version - Git version: Go1.16.5 - Operating system: MacOS <!-- Please include information on whether you built gitea yourself, used one of our downloads or are using some other package --> Local build <!-- Please also tell us how you are running gitea, e.g. if it is being run from docker, a command-line, systemd etc. ---> <!-- If you are using a package or systemd tell us what distribution you are using --> - Database (use `[x]`): - [ x] PostgreSQL - [ ] MySQL - [ ] MSSQL - [ ] SQLite - Can you reproduce the bug at https://try.gitea.io: - [ ] Yes (provide example URL) - [ ] No - Log gist: <!-- It really is important to provide pertinent logs --> <!-- Please read https://docs.gitea.io/en-us/logging-configuration/#debugging-problems --> <!-- In addition, if your problem relates to git commands set `RUN_MODE=dev` at the top of app.ini --> ``` 2021/08/18 16:40:50 Started GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=nW0EacrKHDgc759qF-DtUrECeWb9F3r-s0TYmJoqSf4%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=RklWldnT8ICsWZnzw8YIHW-YgYZLD5oGzwK065XuUm0 for [::1]:53035 2021/08/18 16:40:50 Completed GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=nW0EacrKHDgc759qF-DtUrECeWb9F3r-s0TYmJoqSf4%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=RklWldnT8ICsWZnzw8YIHW-YgYZLD5oGzwK065XuUm0 302 Found in 399.91µs 2021/08/18 16:40:50 Started GET /user/login for [::1]:53035 2021/08/18 16:40:50 Completed GET /user/login 200 OK in 2.780976ms 2021/08/18 16:40:52 Started POST /user/login for [::1]:53035 2021/08/18 16:40:53 Completed POST /user/login 302 Found in 18.950178ms 2021/08/18 16:40:53 Started GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=nW0EacrKHDgc759qF-DtUrECeWb9F3r-s0TYmJoqSf4%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=RklWldnT8ICsWZnzw8YIHW-YgYZLD5oGzwK065XuUm0 for [::1]:53035 2021/08/18 16:40:53 Completed GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=nW0EacrKHDgc759qF-DtUrECeWb9F3r-s0TYmJoqSf4%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=RklWldnT8ICsWZnzw8YIHW-YgYZLD5oGzwK065XuUm0 302 Found in 4.041186ms 2021/08/18 16:40:53 Started POST /login/oauth/access_token for 127.0.0.1:53056 2021/08/18 16:40:53 Completed POST /login/oauth/access_token 200 OK in 91.736432ms 2021/08/18 16:40:53 Started GET /login/oauth/keys for 127.0.0.1:53056 2021/08/18 16:40:53 Completed GET /login/oauth/keys 200 OK in 226.173µs 2021/08/18 16:40:53 Started GET /login/oauth/userinfo for 127.0.0.1:53056 2021/08/18 16:40:53 Completed GET /login/oauth/userinfo 200 OK in 1.249603ms 2021/08/18 16:41:02 Started POST /api/v1/repos/gitea-admin/java-code-templete/generate?access_token=Token%20eyJhbGciOiJSUzI1NiIsImtpZCI6Ikd5OW0ybUxRVFNvYldYMGRYWWRMRzN6SFo2Vi1TQ28zcnJ0MzhwUG9IUmciLCJ0eXAiOiJKV1QifQ.eyJnbnQiOjEsInR0IjowLCJleHAiOjE2MjkzMzM2NTMsImlhdCI6MTYyOTMzMDA1M30.koMiQefEBThIXoqhDdEPbomEhNtFzUX7sT2FtAolwYt4kdPtVMlMzU6Uz80NGNkD7qlRksP2lh48ZK0FeC6cNDdHqkydXFZC09cks4Ldlq9vCbf-kfkQykh9dLzP4Cn8ElZp6bBPyiuWnuoO3OV64UMdT8ZkIE939ivw8m8kL0U4UkmILggoHCPwX42YDKKa7j6_BH8YECCptd4NYUur8hwolbVApbUYx_o0A-DjsU_bl6S6YrmgpAiJIVEEyvVH-3ubPQYs8R9KeDc_8L4H3KpXTi70WTCnlE2AtApuFiOYpdIjmvOv_bhd5G1f208kEbxYui5TpWXUbjPkaLXay16hY5dsatLLMt_q8QvN4_aj0NkbSKsbwRYwHUm8Y0Mr_GJVXsCCi9KSKrDfWDphGArCJAYPd31N3m0or2PgcQ-qazJHctcin58OkULPgX6uKGaayo8eMDsJbpMg_h9F8YM6A5fz48oRM7BxM8F88khhnziUniRwwjszdTVR3hm7-FvbvZatVAU-SlGUsl7c8TBqzpGbFIazeQO7kBQYH7hrIRj-2r80kU_-t_WjUd8FZNgO-AudeB55MhEr6b__tZyNO_5ZjuEBDfQJwf-6rTQ5_3DPxH43kWY9t3WBacZXIHvFxNt3ERMuZiHvtPsZ91PQHxvcJW4NmO6K7BIqxKo for 127.0.0.1:53152 2021/08/18 16:41:02 Completed POST /api/v1/repos/gitea-admin/java-code-templete/generate?access_token=Token%20eyJhbGciOiJSUzI1NiIsImtpZCI6Ikd5OW0ybUxRVFNvYldYMGRYWWRMRzN6SFo2Vi1TQ28zcnJ0MzhwUG9IUmciLCJ0eXAiOiJKV1QifQ.eyJnbnQiOjEsInR0IjowLCJleHAiOjE2MjkzMzM2NTMsImlhdCI6MTYyOTMzMDA1M30.koMiQefEBThIXoqhDdEPbomEhNtFzUX7sT2FtAolwYt4kdPtVMlMzU6Uz80NGNkD7qlRksP2lh48ZK0FeC6cNDdHqkydXFZC09cks4Ldlq9vCbf-kfkQykh9dLzP4Cn8ElZp6bBPyiuWnuoO3OV64UMdT8ZkIE939ivw8m8kL0U4UkmILggoHCPwX42YDKKa7j6_BH8YECCptd4NYUur8hwolbVApbUYx_o0A-DjsU_bl6S6YrmgpAiJIVEEyvVH-3ubPQYs8R9KeDc_8L4H3KpXTi70WTCnlE2AtApuFiOYpdIjmvOv_bhd5G1f208kEbxYui5TpWXUbjPkaLXay16hY5dsatLLMt_q8QvN4_aj0NkbSKsbwRYwHUm8Y0Mr_GJVXsCCi9KSKrDfWDphGArCJAYPd31N3m0or2PgcQ-qazJHctcin58OkULPgX6uKGaayo8eMDsJbpMg_h9F8YM6A5fz48oRM7BxM8F88khhnziUniRwwjszdTVR3hm7-FvbvZatVAU-SlGUsl7c8TBqzpGbFIazeQO7kBQYH7hrIRj-2r80kU_-t_WjUd8FZNgO-AudeB55MhEr6b__tZyNO_5ZjuEBDfQJwf-6rTQ5_3DPxH43kWY9t3WBacZXIHvFxNt3ERMuZiHvtPsZ91PQHxvcJW4NmO6K7BIqxKo 401 Unauthorized in 2.26503ms ``` ``` 2021/08/18 16:51:08 Started GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=VZSxpNjwFxnyiQAmCcakOg-3lfiAtU8vgRTTQJCV42Q%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=sMUUvQmd_1kB_oN0rm35Hj8dyUuM6DGgEQBBuOsBdwY for [::1]:56323 2021/08/18 16:51:08 Completed GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=VZSxpNjwFxnyiQAmCcakOg-3lfiAtU8vgRTTQJCV42Q%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=sMUUvQmd_1kB_oN0rm35Hj8dyUuM6DGgEQBBuOsBdwY 302 Found in 217.028µs 2021/08/18 16:51:08 Started GET /user/login for [::1]:56323 2021/08/18 16:51:08 Completed GET /user/login 200 OK in 1.873134ms 2021/08/18 16:51:10 Started POST /user/login for [::1]:56323 2021/08/18 16:51:10 Completed POST /user/login 302 Found in 20.930799ms 2021/08/18 16:51:10 Started GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=VZSxpNjwFxnyiQAmCcakOg-3lfiAtU8vgRTTQJCV42Q%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=sMUUvQmd_1kB_oN0rm35Hj8dyUuM6DGgEQBBuOsBdwY for [::1]:56323 2021/08/18 16:51:10 Completed GET /login/oauth/authorize?response_type=code&client_id=564a1ee4-7b37-4eb3-a2b7-aa53a5a18811&scope=openid%20profile%20email&state=VZSxpNjwFxnyiQAmCcakOg-3lfiAtU8vgRTTQJCV42Q%3D&redirect_uri=http://localhost:9000/login/oauth2/code/oidc&nonce=sMUUvQmd_1kB_oN0rm35Hj8dyUuM6DGgEQBBuOsBdwY 302 Found in 3.536243ms 2021/08/18 16:51:10 Started POST /login/oauth/access_token for 127.0.0.1:56366 2021/08/18 16:51:10 Completed POST /login/oauth/access_token 200 OK in 90.175249ms 2021/08/18 16:51:10 Started GET /login/oauth/keys for 127.0.0.1:56366 2021/08/18 16:51:10 Completed GET /login/oauth/keys 200 OK in 196.868µs 2021/08/18 16:51:10 Started GET /login/oauth/userinfo for 127.0.0.1:56366 2021/08/18 16:51:10 Completed GET /login/oauth/userinfo 200 OK in 1.760741ms 2021/08/18 16:52:02 Started POST /api/v1/repos/gitea-admin/java-code-templete/generate?sudo=Token%20eyJhbGciOiJSUzI1NiIsImtpZCI6Ikd5OW0ybUxRVFNvYldYMGRYWWRMRzN6SFo2Vi1TQ28zcnJ0MzhwUG9IUmciLCJ0eXAiOiJKV1QifQ.eyJnbnQiOjEsInR0IjowLCJleHAiOjE2MjkzMzQyNzAsImlhdCI6MTYyOTMzMDY3MH0.G-nBxJ6k9j1OJLhga93K21PXljhCZQfyIVjNH_N4CLpzJUVf_82M9OOIDWCm2rmkshsDO42SJaCB2Fj_2KdNaIOBZFEKy94zfLMl9N3CBYlUqoGwJT9RKXgMR950tepfyHd0q0N-wE7FZiEtPs1aYXsRFsU1po-yAdx0YNVSUFEJOZEQjiS0Mo6E82GeeTiTZC5otGjG3HIuMK8s5qV86BDFcDI9obiued24zZKXDbWdshovWy2edM-i9fPqJazqvsnJPnUTLprsoEs9DubtPeE3UL3WXQr6LAPFDzlltITv1ljM7vcwo_geEBcVit4aB2bx6fxGkWgLqoUYS8xPhu0QWaCFN-MW8BGU0aOFzziFj0El8rRvh9jAzEIJIvU6nTTsY7hd3AFfVRevPCCI8bDpq5ok0rLgD-_kCsFz9jCjK6R5YyGSzFaxM5BRkXiY9n-T8-fS6kiJMvE_5wo4VdKqQZn8XckIUNcWT4ep_lXpF6CLLZcfnPrVVh-EQsp46LF0yqGodU6Isv-y3eDA2vFU38VxfvBKhQ2TQGs43jwAe9aEqAQkrKo1rNJPTnA2ySgFxAk8RxBXKxmHASmwt5Qtdf6jKik1AcbUwAapKLeBNlZLwQ444WmmgjM4WC-sQObLvcq97ezPV8ymUOGYm4zk-RbXLH9kVUKijyffu0A for 127.0.0.1:56679 2021/08/18 16:52:02 Completed POST /api/v1/repos/gitea-admin/java-code-templete/generate?sudo=Token%20eyJhbGciOiJSUzI1NiIsImtpZCI6Ikd5OW0ybUxRVFNvYldYMGRYWWRMRzN6SFo2Vi1TQ28zcnJ0MzhwUG9IUmciLCJ0eXAiOiJKV1QifQ.eyJnbnQiOjEsInR0IjowLCJleHAiOjE2MjkzMzQyNzAsImlhdCI6MTYyOTMzMDY3MH0.G-nBxJ6k9j1OJLhga93K21PXljhCZQfyIVjNH_N4CLpzJUVf_82M9OOIDWCm2rmkshsDO42SJaCB2Fj_2KdNaIOBZFEKy94zfLMl9N3CBYlUqoGwJT9RKXgMR950tepfyHd0q0N-wE7FZiEtPs1aYXsRFsU1po-yAdx0YNVSUFEJOZEQjiS0Mo6E82GeeTiTZC5otGjG3HIuMK8s5qV86BDFcDI9obiued24zZKXDbWdshovWy2edM-i9fPqJazqvsnJPnUTLprsoEs9DubtPeE3UL3WXQr6LAPFDzlltITv1ljM7vcwo_geEBcVit4aB2bx6fxGkWgLqoUYS8xPhu0QWaCFN-MW8BGU0aOFzziFj0El8rRvh9jAzEIJIvU6nTTsY7hd3AFfVRevPCCI8bDpq5ok0rLgD-_kCsFz9jCjK6R5YyGSzFaxM5BRkXiY9n-T8-fS6kiJMvE_5wo4VdKqQZn8XckIUNcWT4ep_lXpF6CLLZcfnPrVVh-EQsp46LF0yqGodU6Isv-y3eDA2vFU38VxfvBKhQ2TQGs43jwAe9aEqAQkrKo1rNJPTnA2ySgFxAk8RxBXKxmHASmwt5Qtdf6jKik1AcbUwAapKLeBNlZLwQ444WmmgjM4WC-sQObLvcq97ezPV8ymUOGYm4zk-RbXLH9kVUKijyffu0A 403 Forbidden in 219.906µs ``` ## Description <!-- If using a proxy or a CDN (e.g. CloudFlare) in front of gitea, please disable the proxy/CDN fully and connect to gitea directly to confirm the issue still persists without those services. --> A Java code consumes the API: ``` private ResponseEntity<?> generateRepo(String templateOwner, String templateRepo, io.gitea.model.GenerateRepoOption body, String tokenValue){ ApiClient client = Configuration.getDefaultApiClient(); client.setBasePath("http://localhost:3000/api/v1"); // Configure API key authorization: SudoParam ApiKeyAuth SudoParam = (ApiKeyAuth) client.getAuthentication("AccessToken");//getAuthentication("SudoParam"); // Unauthorized vs Forbidden SudoParam.setApiKey(tokenValue); // Uncomment the following line to set a prefix for the API key, e.g. "Token" (defaults to null) SudoParam.setApiKeyPrefix("Token"); RepositoryApi apiInstance = new RepositoryApi(); try { io.gitea.model.Repository result = apiInstance.generateRepo(templateOwner, templateRepo, body); return new ResponseEntity<io.gitea.model.Repository>(result, HttpStatus.CREATED); } catch (ApiException e) { String message = e.getMessage(); if(message.contains("403")){ return new ResponseEntity<>(message, HttpStatus.FORBIDDEN); } if(message.contains("404")){ return new ResponseEntity<>(message, HttpStatus.NOT_FOUND); } if(message.contains("409")){ return new ResponseEntity<>(message, HttpStatus.CONFLICT); } if(message.contains("422")){ return new ResponseEntity<>(message, HttpStatus.UNPROCESSABLE_ENTITY); } return new ResponseEntity<>(message, HttpStatus.INTERNAL_SERVER_ERROR); } } ``` The outcome of the above code will be "Unauthorized". And it will be "Forbidden" if replacing the getAuthentication("AccessToken") with getAuthentication("SudoParam"). The first error is normal, a correct behaviour while the second isn't. The access token is obtained with an OAuth login of an admin user account. ... ## Screenshots <!-- **If this issue involves the Web Interface, please include a screenshot** -->
Author
Owner

@techknowlogick commented on GitHub (Aug 19, 2021):

Assuming you are using https://github.com/zeripath/java-gitea-api/, your question is best asked to the SDK you are using.

@techknowlogick commented on GitHub (Aug 19, 2021): Assuming you are using https://github.com/zeripath/java-gitea-api/, your question is best asked to the SDK you are using.
Author
Owner

@vw98075 commented on GitHub (Aug 19, 2021):

Your assumption is correct. I guess the SDK isn't officially supported. Initially, I tried to use those API directly with a HTTP client library. I run into a validation error. I didn't see any additional log messages after turning up the log level to debug. I didn't get any answers to my question on how to figure out the cause for the case. So, I turned to the SDK. It would be much appreciated if you could give me some hints in the regard.

@vw98075 commented on GitHub (Aug 19, 2021): Your assumption is correct. I guess the SDK isn't officially supported. Initially, I tried to use those API directly with a HTTP client library. I run into a validation error. I didn't see any additional log messages after turning up the log level to debug. I didn't get any answers to my question on how to figure out the cause for the case. So, I turned to the SDK. It would be much appreciated if you could give me some hints in the regard.
Author
Owner

@zeripath commented on GitHub (Aug 19, 2021):

Hi @vw98075 it looks like you're not authenticating correctly - open an issue on the java-gitea-api repository though and we can discuss it better.

Remember that this API library is auto-generated including its documentation and some understanding of how you authenticate against Gitea is assumed.

  • If you're using AccessToken or Token authentication - do not set an ApiKeyPrefix. It is not needed.
  • However, you should really use the AuthorizationHeaderToken method and the apiKeyPrefix should be "token" not "Token", (or just prefix your token with "token " as the swagger docs suggest):
        ApiKeyAuth AuthorizationHeaderToken = (ApiKeyAuth) defaultClient.getAuthentication("AuthorizationHeaderToken");
        AuthorizationHeaderToken.setApiKey("YOUR API KEY");
        AuthorizationHeaderToken.setApiKeyPrefix("token"); // As the swagger docs state: API tokens must be prepended with \"token\" followed by a space.
  • One of the SudoHeader and SudoParam can be used in addition to above and should only be used by when authenticating as an admin to become a different user. The ApiKey for these would then simply be the username of the user to sudo as.
@zeripath commented on GitHub (Aug 19, 2021): Hi @vw98075 it looks like you're not authenticating correctly - open an issue on the java-gitea-api repository though and we can discuss it better. Remember that this API library is auto-generated including its documentation and some understanding of how you authenticate against Gitea is assumed. * If you're using `AccessToken` or `Token` authentication - do not set an ApiKeyPrefix. It is not needed. * However, you should really use the `AuthorizationHeaderToken` method and the apiKeyPrefix should be "token" not "Token", (or just prefix your token with "token " as the swagger docs suggest): ```java ApiKeyAuth AuthorizationHeaderToken = (ApiKeyAuth) defaultClient.getAuthentication("AuthorizationHeaderToken"); AuthorizationHeaderToken.setApiKey("YOUR API KEY"); AuthorizationHeaderToken.setApiKeyPrefix("token"); // As the swagger docs state: API tokens must be prepended with \"token\" followed by a space. ``` * One of the SudoHeader and SudoParam can be used in addition to above and should only be used by when authenticating as an admin to become a different user. The `ApiKey` for these would then simply be the username of the user to sudo as.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/gitea#7708