The backend now has a global AuthGateMiddleware: every data route
(workspaces/lookup, upload-agent, sse/...) requires auth, returning
401 {"detail":"authentication required"} otherwise. CI authenticates with
the service token via the X-Admin-Token header (proxies any user_id).
- run_agent_api.py: read ADMIN_API_TOKEN from env, attach X-Admin-Token to
both httpx clients (all lookup/upload/sse/action/cancel calls); warn if unset
- run-agent.yml: inject ADMIN_API_TOKEN from Gitea repo secret
- Gitea repo secret ADMIN_API_TOKEN registered
- TEST_WORKFLOW.md / .env.example: document ADMIN_API_TOKEN (.env local, secret in CI)
Verified end-to-end: workspaces/lookup for user_id=jhogyu now resolves
(401 -> 200), e.g. Aug_2026_Test -> 3523fa2b-...
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
user_id is now a required workflow_dispatch input (no default) and the
runner validates it is non-empty before doing anything. Removed the
'jsahn' default from the script arg and replaced jsahn with <user_id>
placeholders throughout TEST_WORKFLOW.md so the workflow is not pinned
to one account.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- Documented the workflow for running Agent YAML using Gitea Actions.
- Included setup instructions for .env file with Gitea token.
- Provided three methods for triggering the workflow: via Gitea API, Gitea web UI, and local script execution.
- Added workflow input reference and prerequisites for server infrastructure.
- Included troubleshooting section for common issues encountered during execution.