From 730af0a33535f46bc7755574d2ad013629cfbf8c Mon Sep 17 00:00:00 2001 From: Octoturge Date: Thu, 27 Aug 2026 00:49:20 +0200 Subject: [PATCH] cli-setup-wizard: stop parsing tea's config.yml, use tea itself DID_GITEA detection and the SSH/GPG key uploads to Gitea were reading tea's config.yml directly with awk, assuming 2-space indentation and a plaintext `token:` field. Neither holds: the real format uses 6-space indentation for fields under each login, and a login done via OAuth (tea's default flow) has no token field in the file at all - it's held elsewhere. Confirmed live: a workspace with a genuinely active `tea` OAuth login was still reporting "not logged in" and skipping the whole key-setup step because of this. Replaced with tea's own subcommands, which handle auth internally regardless of method: - detection: `tea whoami` - SSH key upload: `tea ssh-keys add` - GPG key upload: `tea api -X POST /user/gpg_keys -F armored_public_key=@-` Verified all three directly against the live account (disposable test SSH + GPG keys, added then removed) - SSH upload succeeded; the GPG upload correctly failed for an unrelated, expected reason (Gitea requires the key's email to match a verified account email, and the test key used a throwaway address), confirming the request itself is well-formed. --- templates/3d-printing/cli-setup-wizard.sh | 25 ++++++++--------------- templates/cobol/cli-setup-wizard.sh | 25 ++++++++--------------- templates/default/cli-setup-wizard.sh | 25 ++++++++--------------- templates/python/cli-setup-wizard.sh | 25 ++++++++--------------- templates/ttrpg/cli-setup-wizard.sh | 25 ++++++++--------------- templates/web/cli-setup-wizard.sh | 25 ++++++++--------------- 6 files changed, 54 insertions(+), 96 deletions(-) diff --git a/templates/3d-printing/cli-setup-wizard.sh b/templates/3d-printing/cli-setup-wizard.sh index 91de88e..f50d0c3 100644 --- a/templates/3d-printing/cli-setup-wizard.sh +++ b/templates/3d-printing/cli-setup-wizard.sh @@ -143,12 +143,11 @@ else fi fi fi -TEA_CONFIG="${XDG_CONFIG_HOME:-$HOME/.config}/tea/config.yml" -if command -v tea >/dev/null 2>&1 && [ -f "$TEA_CONFIG" ]; then - TEA_URL="$(awk '/^logins:/{f=1} f && /^ url:/{print $2; exit}' "$TEA_CONFIG")" - TEA_TOKEN="$(awk '/^logins:/{f=1} f && /^ token:/{print $2; exit}' "$TEA_CONFIG")" - [ -n "$TEA_URL" ] && [ -n "$TEA_TOKEN" ] && DID_GITEA=1 -fi +# `tea whoami` succeeds regardless of how the login was done (personal +# access token or OAuth) - more reliable than parsing tea's own +# config.yml, whose indentation and fields (no plaintext `token:` at all +# for an OAuth login) vary by auth method. +command -v tea >/dev/null 2>&1 && tea whoami >/dev/null 2>&1 && DID_GITEA=1 # --- SSH + GPG keys for the external git host(s) selected above --- # Only asks if the user actually set up GitHub and/or Gitea just now - @@ -186,13 +185,10 @@ if [ "$DID_GITHUB" -eq 1 ] || [ "$DID_GITEA" -eq 1 ]; then fi if [ "$DID_GITEA" -eq 1 ]; then - SSH_PUB_JSON="$(sed 's/\\/\\\\/g; s/"/\\"/g' "${SSH_KEY}.pub")" - if curl -fsS -X POST "${TEA_URL%/}/api/v1/user/keys" \ - -H "Authorization: token ${TEA_TOKEN}" -H "Content-Type: application/json" \ - -d "{\"title\":\"coder-$(hostname)\",\"key\":\"${SSH_PUB_JSON}\"}" >/dev/null 2>&1; then + if tea ssh-keys add "${SSH_KEY}.pub" --title "coder-$(hostname)" >/dev/null 2>&1; then echo "SSH key added to Gitea." else - echo "Couldn't add the SSH key to Gitea automatically (may already be added). Add manually at: ${TEA_URL%/}/user/settings/keys" + echo "Couldn't add the SSH key to Gitea automatically (may already be added). Add manually with: tea ssh-keys add ${SSH_KEY}.pub" fi fi @@ -226,13 +222,10 @@ if [ "$DID_GITHUB" -eq 1 ] || [ "$DID_GITEA" -eq 1 ]; then fi if [ "$DID_GITEA" -eq 1 ]; then - GPG_ARMORED_JSON="$(gpg --armor --export "$GPG_KEY_ID" | awk '{printf "%s\\n", $0}')" - if curl -fsS -X POST "${TEA_URL%/}/api/v1/user/gpg_keys" \ - -H "Authorization: token ${TEA_TOKEN}" -H "Content-Type: application/json" \ - -d "{\"armored_public_key\":\"${GPG_ARMORED_JSON}\"}" >/dev/null 2>&1; then + if gpg --armor --export "$GPG_KEY_ID" | tea api -X POST /user/gpg_keys -F armored_public_key=@- >/dev/null 2>&1; then echo "GPG key added to Gitea." else - echo "Couldn't add the GPG key to Gitea automatically (may already be added). Add manually at: ${TEA_URL%/}/user/settings/keys" + echo "Couldn't add the GPG key to Gitea automatically (may already be added). Add manually: gpg --armor --export $GPG_KEY_ID | tea api -X POST /user/gpg_keys -F armored_public_key=@-" fi fi fi diff --git a/templates/cobol/cli-setup-wizard.sh b/templates/cobol/cli-setup-wizard.sh index 91de88e..f50d0c3 100644 --- a/templates/cobol/cli-setup-wizard.sh +++ b/templates/cobol/cli-setup-wizard.sh @@ -143,12 +143,11 @@ else fi fi fi -TEA_CONFIG="${XDG_CONFIG_HOME:-$HOME/.config}/tea/config.yml" -if command -v tea >/dev/null 2>&1 && [ -f "$TEA_CONFIG" ]; then - TEA_URL="$(awk '/^logins:/{f=1} f && /^ url:/{print $2; exit}' "$TEA_CONFIG")" - TEA_TOKEN="$(awk '/^logins:/{f=1} f && /^ token:/{print $2; exit}' "$TEA_CONFIG")" - [ -n "$TEA_URL" ] && [ -n "$TEA_TOKEN" ] && DID_GITEA=1 -fi +# `tea whoami` succeeds regardless of how the login was done (personal +# access token or OAuth) - more reliable than parsing tea's own +# config.yml, whose indentation and fields (no plaintext `token:` at all +# for an OAuth login) vary by auth method. +command -v tea >/dev/null 2>&1 && tea whoami >/dev/null 2>&1 && DID_GITEA=1 # --- SSH + GPG keys for the external git host(s) selected above --- # Only asks if the user actually set up GitHub and/or Gitea just now - @@ -186,13 +185,10 @@ if [ "$DID_GITHUB" -eq 1 ] || [ "$DID_GITEA" -eq 1 ]; then fi if [ "$DID_GITEA" -eq 1 ]; then - SSH_PUB_JSON="$(sed 's/\\/\\\\/g; s/"/\\"/g' "${SSH_KEY}.pub")" - if curl -fsS -X POST "${TEA_URL%/}/api/v1/user/keys" \ - -H "Authorization: token ${TEA_TOKEN}" -H "Content-Type: application/json" \ - -d "{\"title\":\"coder-$(hostname)\",\"key\":\"${SSH_PUB_JSON}\"}" >/dev/null 2>&1; then + if tea ssh-keys add "${SSH_KEY}.pub" --title "coder-$(hostname)" >/dev/null 2>&1; then echo "SSH key added to Gitea." else - echo "Couldn't add the SSH key to Gitea automatically (may already be added). Add manually at: ${TEA_URL%/}/user/settings/keys" + echo "Couldn't add the SSH key to Gitea automatically (may already be added). Add manually with: tea ssh-keys add ${SSH_KEY}.pub" fi fi @@ -226,13 +222,10 @@ if [ "$DID_GITHUB" -eq 1 ] || [ "$DID_GITEA" -eq 1 ]; then fi if [ "$DID_GITEA" -eq 1 ]; then - GPG_ARMORED_JSON="$(gpg --armor --export "$GPG_KEY_ID" | awk '{printf "%s\\n", $0}')" - if curl -fsS -X POST "${TEA_URL%/}/api/v1/user/gpg_keys" \ - -H "Authorization: token ${TEA_TOKEN}" -H "Content-Type: application/json" \ - -d "{\"armored_public_key\":\"${GPG_ARMORED_JSON}\"}" >/dev/null 2>&1; then + if gpg --armor --export "$GPG_KEY_ID" | tea api -X POST /user/gpg_keys -F armored_public_key=@- >/dev/null 2>&1; then echo "GPG key added to Gitea." else - echo "Couldn't add the GPG key to Gitea automatically (may already be added). Add manually at: ${TEA_URL%/}/user/settings/keys" + echo "Couldn't add the GPG key to Gitea automatically (may already be added). Add manually: gpg --armor --export $GPG_KEY_ID | tea api -X POST /user/gpg_keys -F armored_public_key=@-" fi fi fi diff --git a/templates/default/cli-setup-wizard.sh b/templates/default/cli-setup-wizard.sh index 91de88e..f50d0c3 100644 --- a/templates/default/cli-setup-wizard.sh +++ b/templates/default/cli-setup-wizard.sh @@ -143,12 +143,11 @@ else fi fi fi -TEA_CONFIG="${XDG_CONFIG_HOME:-$HOME/.config}/tea/config.yml" -if command -v tea >/dev/null 2>&1 && [ -f "$TEA_CONFIG" ]; then - TEA_URL="$(awk '/^logins:/{f=1} f && /^ url:/{print $2; exit}' "$TEA_CONFIG")" - TEA_TOKEN="$(awk '/^logins:/{f=1} f && /^ token:/{print $2; exit}' "$TEA_CONFIG")" - [ -n "$TEA_URL" ] && [ -n "$TEA_TOKEN" ] && DID_GITEA=1 -fi +# `tea whoami` succeeds regardless of how the login was done (personal +# access token or OAuth) - more reliable than parsing tea's own +# config.yml, whose indentation and fields (no plaintext `token:` at all +# for an OAuth login) vary by auth method. +command -v tea >/dev/null 2>&1 && tea whoami >/dev/null 2>&1 && DID_GITEA=1 # --- SSH + GPG keys for the external git host(s) selected above --- # Only asks if the user actually set up GitHub and/or Gitea just now - @@ -186,13 +185,10 @@ if [ "$DID_GITHUB" -eq 1 ] || [ "$DID_GITEA" -eq 1 ]; then fi if [ "$DID_GITEA" -eq 1 ]; then - SSH_PUB_JSON="$(sed 's/\\/\\\\/g; s/"/\\"/g' "${SSH_KEY}.pub")" - if curl -fsS -X POST "${TEA_URL%/}/api/v1/user/keys" \ - -H "Authorization: token ${TEA_TOKEN}" -H "Content-Type: application/json" \ - -d "{\"title\":\"coder-$(hostname)\",\"key\":\"${SSH_PUB_JSON}\"}" >/dev/null 2>&1; then + if tea ssh-keys add "${SSH_KEY}.pub" --title "coder-$(hostname)" >/dev/null 2>&1; then echo "SSH key added to Gitea." else - echo "Couldn't add the SSH key to Gitea automatically (may already be added). Add manually at: ${TEA_URL%/}/user/settings/keys" + echo "Couldn't add the SSH key to Gitea automatically (may already be added). Add manually with: tea ssh-keys add ${SSH_KEY}.pub" fi fi @@ -226,13 +222,10 @@ if [ "$DID_GITHUB" -eq 1 ] || [ "$DID_GITEA" -eq 1 ]; then fi if [ "$DID_GITEA" -eq 1 ]; then - GPG_ARMORED_JSON="$(gpg --armor --export "$GPG_KEY_ID" | awk '{printf "%s\\n", $0}')" - if curl -fsS -X POST "${TEA_URL%/}/api/v1/user/gpg_keys" \ - -H "Authorization: token ${TEA_TOKEN}" -H "Content-Type: application/json" \ - -d "{\"armored_public_key\":\"${GPG_ARMORED_JSON}\"}" >/dev/null 2>&1; then + if gpg --armor --export "$GPG_KEY_ID" | tea api -X POST /user/gpg_keys -F armored_public_key=@- >/dev/null 2>&1; then echo "GPG key added to Gitea." else - echo "Couldn't add the GPG key to Gitea automatically (may already be added). Add manually at: ${TEA_URL%/}/user/settings/keys" + echo "Couldn't add the GPG key to Gitea automatically (may already be added). Add manually: gpg --armor --export $GPG_KEY_ID | tea api -X POST /user/gpg_keys -F armored_public_key=@-" fi fi fi diff --git a/templates/python/cli-setup-wizard.sh b/templates/python/cli-setup-wizard.sh index 91de88e..f50d0c3 100644 --- a/templates/python/cli-setup-wizard.sh +++ b/templates/python/cli-setup-wizard.sh @@ -143,12 +143,11 @@ else fi fi fi -TEA_CONFIG="${XDG_CONFIG_HOME:-$HOME/.config}/tea/config.yml" -if command -v tea >/dev/null 2>&1 && [ -f "$TEA_CONFIG" ]; then - TEA_URL="$(awk '/^logins:/{f=1} f && /^ url:/{print $2; exit}' "$TEA_CONFIG")" - TEA_TOKEN="$(awk '/^logins:/{f=1} f && /^ token:/{print $2; exit}' "$TEA_CONFIG")" - [ -n "$TEA_URL" ] && [ -n "$TEA_TOKEN" ] && DID_GITEA=1 -fi +# `tea whoami` succeeds regardless of how the login was done (personal +# access token or OAuth) - more reliable than parsing tea's own +# config.yml, whose indentation and fields (no plaintext `token:` at all +# for an OAuth login) vary by auth method. +command -v tea >/dev/null 2>&1 && tea whoami >/dev/null 2>&1 && DID_GITEA=1 # --- SSH + GPG keys for the external git host(s) selected above --- # Only asks if the user actually set up GitHub and/or Gitea just now - @@ -186,13 +185,10 @@ if [ "$DID_GITHUB" -eq 1 ] || [ "$DID_GITEA" -eq 1 ]; then fi if [ "$DID_GITEA" -eq 1 ]; then - SSH_PUB_JSON="$(sed 's/\\/\\\\/g; s/"/\\"/g' "${SSH_KEY}.pub")" - if curl -fsS -X POST "${TEA_URL%/}/api/v1/user/keys" \ - -H "Authorization: token ${TEA_TOKEN}" -H "Content-Type: application/json" \ - -d "{\"title\":\"coder-$(hostname)\",\"key\":\"${SSH_PUB_JSON}\"}" >/dev/null 2>&1; then + if tea ssh-keys add "${SSH_KEY}.pub" --title "coder-$(hostname)" >/dev/null 2>&1; then echo "SSH key added to Gitea." else - echo "Couldn't add the SSH key to Gitea automatically (may already be added). Add manually at: ${TEA_URL%/}/user/settings/keys" + echo "Couldn't add the SSH key to Gitea automatically (may already be added). Add manually with: tea ssh-keys add ${SSH_KEY}.pub" fi fi @@ -226,13 +222,10 @@ if [ "$DID_GITHUB" -eq 1 ] || [ "$DID_GITEA" -eq 1 ]; then fi if [ "$DID_GITEA" -eq 1 ]; then - GPG_ARMORED_JSON="$(gpg --armor --export "$GPG_KEY_ID" | awk '{printf "%s\\n", $0}')" - if curl -fsS -X POST "${TEA_URL%/}/api/v1/user/gpg_keys" \ - -H "Authorization: token ${TEA_TOKEN}" -H "Content-Type: application/json" \ - -d "{\"armored_public_key\":\"${GPG_ARMORED_JSON}\"}" >/dev/null 2>&1; then + if gpg --armor --export "$GPG_KEY_ID" | tea api -X POST /user/gpg_keys -F armored_public_key=@- >/dev/null 2>&1; then echo "GPG key added to Gitea." else - echo "Couldn't add the GPG key to Gitea automatically (may already be added). Add manually at: ${TEA_URL%/}/user/settings/keys" + echo "Couldn't add the GPG key to Gitea automatically (may already be added). Add manually: gpg --armor --export $GPG_KEY_ID | tea api -X POST /user/gpg_keys -F armored_public_key=@-" fi fi fi diff --git a/templates/ttrpg/cli-setup-wizard.sh b/templates/ttrpg/cli-setup-wizard.sh index 91de88e..f50d0c3 100644 --- a/templates/ttrpg/cli-setup-wizard.sh +++ b/templates/ttrpg/cli-setup-wizard.sh @@ -143,12 +143,11 @@ else fi fi fi -TEA_CONFIG="${XDG_CONFIG_HOME:-$HOME/.config}/tea/config.yml" -if command -v tea >/dev/null 2>&1 && [ -f "$TEA_CONFIG" ]; then - TEA_URL="$(awk '/^logins:/{f=1} f && /^ url:/{print $2; exit}' "$TEA_CONFIG")" - TEA_TOKEN="$(awk '/^logins:/{f=1} f && /^ token:/{print $2; exit}' "$TEA_CONFIG")" - [ -n "$TEA_URL" ] && [ -n "$TEA_TOKEN" ] && DID_GITEA=1 -fi +# `tea whoami` succeeds regardless of how the login was done (personal +# access token or OAuth) - more reliable than parsing tea's own +# config.yml, whose indentation and fields (no plaintext `token:` at all +# for an OAuth login) vary by auth method. +command -v tea >/dev/null 2>&1 && tea whoami >/dev/null 2>&1 && DID_GITEA=1 # --- SSH + GPG keys for the external git host(s) selected above --- # Only asks if the user actually set up GitHub and/or Gitea just now - @@ -186,13 +185,10 @@ if [ "$DID_GITHUB" -eq 1 ] || [ "$DID_GITEA" -eq 1 ]; then fi if [ "$DID_GITEA" -eq 1 ]; then - SSH_PUB_JSON="$(sed 's/\\/\\\\/g; s/"/\\"/g' "${SSH_KEY}.pub")" - if curl -fsS -X POST "${TEA_URL%/}/api/v1/user/keys" \ - -H "Authorization: token ${TEA_TOKEN}" -H "Content-Type: application/json" \ - -d "{\"title\":\"coder-$(hostname)\",\"key\":\"${SSH_PUB_JSON}\"}" >/dev/null 2>&1; then + if tea ssh-keys add "${SSH_KEY}.pub" --title "coder-$(hostname)" >/dev/null 2>&1; then echo "SSH key added to Gitea." else - echo "Couldn't add the SSH key to Gitea automatically (may already be added). Add manually at: ${TEA_URL%/}/user/settings/keys" + echo "Couldn't add the SSH key to Gitea automatically (may already be added). Add manually with: tea ssh-keys add ${SSH_KEY}.pub" fi fi @@ -226,13 +222,10 @@ if [ "$DID_GITHUB" -eq 1 ] || [ "$DID_GITEA" -eq 1 ]; then fi if [ "$DID_GITEA" -eq 1 ]; then - GPG_ARMORED_JSON="$(gpg --armor --export "$GPG_KEY_ID" | awk '{printf "%s\\n", $0}')" - if curl -fsS -X POST "${TEA_URL%/}/api/v1/user/gpg_keys" \ - -H "Authorization: token ${TEA_TOKEN}" -H "Content-Type: application/json" \ - -d "{\"armored_public_key\":\"${GPG_ARMORED_JSON}\"}" >/dev/null 2>&1; then + if gpg --armor --export "$GPG_KEY_ID" | tea api -X POST /user/gpg_keys -F armored_public_key=@- >/dev/null 2>&1; then echo "GPG key added to Gitea." else - echo "Couldn't add the GPG key to Gitea automatically (may already be added). Add manually at: ${TEA_URL%/}/user/settings/keys" + echo "Couldn't add the GPG key to Gitea automatically (may already be added). Add manually: gpg --armor --export $GPG_KEY_ID | tea api -X POST /user/gpg_keys -F armored_public_key=@-" fi fi fi diff --git a/templates/web/cli-setup-wizard.sh b/templates/web/cli-setup-wizard.sh index 91de88e..f50d0c3 100644 --- a/templates/web/cli-setup-wizard.sh +++ b/templates/web/cli-setup-wizard.sh @@ -143,12 +143,11 @@ else fi fi fi -TEA_CONFIG="${XDG_CONFIG_HOME:-$HOME/.config}/tea/config.yml" -if command -v tea >/dev/null 2>&1 && [ -f "$TEA_CONFIG" ]; then - TEA_URL="$(awk '/^logins:/{f=1} f && /^ url:/{print $2; exit}' "$TEA_CONFIG")" - TEA_TOKEN="$(awk '/^logins:/{f=1} f && /^ token:/{print $2; exit}' "$TEA_CONFIG")" - [ -n "$TEA_URL" ] && [ -n "$TEA_TOKEN" ] && DID_GITEA=1 -fi +# `tea whoami` succeeds regardless of how the login was done (personal +# access token or OAuth) - more reliable than parsing tea's own +# config.yml, whose indentation and fields (no plaintext `token:` at all +# for an OAuth login) vary by auth method. +command -v tea >/dev/null 2>&1 && tea whoami >/dev/null 2>&1 && DID_GITEA=1 # --- SSH + GPG keys for the external git host(s) selected above --- # Only asks if the user actually set up GitHub and/or Gitea just now - @@ -186,13 +185,10 @@ if [ "$DID_GITHUB" -eq 1 ] || [ "$DID_GITEA" -eq 1 ]; then fi if [ "$DID_GITEA" -eq 1 ]; then - SSH_PUB_JSON="$(sed 's/\\/\\\\/g; s/"/\\"/g' "${SSH_KEY}.pub")" - if curl -fsS -X POST "${TEA_URL%/}/api/v1/user/keys" \ - -H "Authorization: token ${TEA_TOKEN}" -H "Content-Type: application/json" \ - -d "{\"title\":\"coder-$(hostname)\",\"key\":\"${SSH_PUB_JSON}\"}" >/dev/null 2>&1; then + if tea ssh-keys add "${SSH_KEY}.pub" --title "coder-$(hostname)" >/dev/null 2>&1; then echo "SSH key added to Gitea." else - echo "Couldn't add the SSH key to Gitea automatically (may already be added). Add manually at: ${TEA_URL%/}/user/settings/keys" + echo "Couldn't add the SSH key to Gitea automatically (may already be added). Add manually with: tea ssh-keys add ${SSH_KEY}.pub" fi fi @@ -226,13 +222,10 @@ if [ "$DID_GITHUB" -eq 1 ] || [ "$DID_GITEA" -eq 1 ]; then fi if [ "$DID_GITEA" -eq 1 ]; then - GPG_ARMORED_JSON="$(gpg --armor --export "$GPG_KEY_ID" | awk '{printf "%s\\n", $0}')" - if curl -fsS -X POST "${TEA_URL%/}/api/v1/user/gpg_keys" \ - -H "Authorization: token ${TEA_TOKEN}" -H "Content-Type: application/json" \ - -d "{\"armored_public_key\":\"${GPG_ARMORED_JSON}\"}" >/dev/null 2>&1; then + if gpg --armor --export "$GPG_KEY_ID" | tea api -X POST /user/gpg_keys -F armored_public_key=@- >/dev/null 2>&1; then echo "GPG key added to Gitea." else - echo "Couldn't add the GPG key to Gitea automatically (may already be added). Add manually at: ${TEA_URL%/}/user/settings/keys" + echo "Couldn't add the GPG key to Gitea automatically (may already be added). Add manually: gpg --armor --export $GPG_KEY_ID | tea api -X POST /user/gpg_keys -F armored_public_key=@-" fi fi fi