The backend now has a global AuthGateMiddleware: every data route
(workspaces/lookup, upload-agent, sse/...) requires auth, returning
401 {"detail":"authentication required"} otherwise. CI authenticates with
the service token via the X-Admin-Token header (proxies any user_id).
- run_agent_api.py: read ADMIN_API_TOKEN from env, attach X-Admin-Token to
both httpx clients (all lookup/upload/sse/action/cancel calls); warn if unset
- run-agent.yml: inject ADMIN_API_TOKEN from Gitea repo secret
- Gitea repo secret ADMIN_API_TOKEN registered
- TEST_WORKFLOW.md / .env.example: document ADMIN_API_TOKEN (.env local, secret in CI)
Verified end-to-end: workspaces/lookup for user_id=jhogyu now resolves
(401 -> 200), e.g. Aug_2026_Test -> 3523fa2b-...
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
3 lines
30 B
Bash
3 lines
30 B
Bash
GITEA_TOKEN=
|
|
ADMIN_API_TOKEN=
|