From 26cd05e9619dfe251185303401c3edd9c680db22 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sun, 30 Aug 2026 00:50:35 +1000 Subject: [PATCH] Make the Vault gitea creds path selectable agentpr always read gitea/creds/unkin-agent from a bare const, so a service like repospawner could not run it as its own Gitea identity. - Replace the GiteaCredsPath const with a function: GITEA_CREDS_PATH when set, otherwise gitea/creds/. Unset env still resolves to gitea/creds/unkin-agent, so existing callers are unchanged. - Thread the creds path through fetchGiteaToken/readGiteaCreds instead of reading a package-level const, and report it in the error messages. - Make agentpr's help text login-agnostic and document both variables. --- AGENTS.md | 17 ++-- README.md | 23 ++--- cmd/agentpr/main.go | 14 +-- internal/agent/client_test.go | 13 +-- internal/agent/token.go | 38 ++++++--- internal/agent/token_test.go | 155 ++++++++++++++++++++++++++++++++++ internal/agent/vault.go | 15 ++-- 7 files changed, 227 insertions(+), 48 deletions(-) create mode 100644 internal/agent/token_test.go diff --git a/AGENTS.md b/AGENTS.md index e30517d..b500548 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -3,8 +3,10 @@ ## Project Overview This repo ships several Gitea-automation CLIs in one RPM (`agent-tools`). They -act as the `unkin-agent` user by minting a scoped Gitea token from Vault, so -actions are attributed to the agent rather than to whoever runs the tool. +act as an agent user (`unkin-agent` by default) by minting a scoped Gitea token +from Vault, so actions are attributed to the agent rather than to whoever runs +the tool. Setting `AGENT_LOGIN` selects a different agent identity, so a service +like repospawner can run these tools as itself. - **`agentpr`** — create pull requests and post PR comments as `unkin-agent` (fixes the "tea posts as Ben" attribution problem). Subcommands: @@ -32,7 +34,7 @@ cmd/agentws/main.go # agentws CLI (new / list / rm / clean / token / creden cmd/agentvault/main.go # agentvault CLI (seed-outpost) internal/agent/ # shared plumbing: token.go # env config + in-process Gitea-token cache - vault.go # AppRole login + read gitea/creds/unkin-agent + vault.go # AppRole login + read the gitea creds path gitea.go # Gitea REST client (PR create/get, comments, status, whoami) parse.go # owner/repo#N and owner/repo parsing watch.go # PRState snapshot + MeaningfulChange comparison @@ -57,7 +59,9 @@ All tools call `agent.GiteaToken()`, which (once per process): 1. AppRole login: `POST $VAULT_ADDR/v1/auth/approle/login` with `role_id` only (no `secret_id`) → `client_token`. -2. `GET $VAULT_ADDR/v1/gitea/creds/unkin-agent` with `X-Vault-Token` → `.data.token`. +2. `GET $VAULT_ADDR/v1/` with `X-Vault-Token` → `.data.token`, where + the creds path is `GITEA_CREDS_PATH` if set, else `gitea/creds/$AGENT_LOGIN` + (so unset env still reads `gitea/creds/unkin-agent`). Config via env (all have defaults): @@ -66,7 +70,8 @@ Config via env (all have defaults): | `VAULT_ADDR` | `https://vault.service.consul:8200` | Vault/OpenBao address | | `AGENT_APPROLE_ROLE_ID` | built-in default | AppRole role_id (overridable) | | `GITEA_URL` | `https://git.unkin.net` | Gitea base URL | -| `AGENT_LOGIN` | `unkin-agent` | login whose comments watchpr ignores; agentws git identity | +| `AGENT_LOGIN` | `unkin-agent` | agent identity: selects `gitea/creds/`; login whose comments watchpr ignores; agentws git identity | +| `GITEA_CREDS_PATH` | `gitea/creds/$AGENT_LOGIN` | Vault path minting the Gitea token (wins over `AGENT_LOGIN`) | | `AGENTWS_SRC_ROOT` | `~/src/prodenv` | agentws source-of-truth checkout root | | `AGENTWS_ROOT` | `~/.cache/agentws` | agentws worktree root | | `AGENTWS_OWNER` | `unkin` | Gitea org that owns agentws-managed repos | @@ -77,7 +82,7 @@ Config via env (all have defaults): Gitea tokens are ~1h ephemeral, so `agentws` never bakes one into a remote URL or config. `agentws token` prints a fresh token; `agentws credential get` implements the git credential protocol (reads the key=value request on stdin, -and for the configured Gitea host only emits `username=unkin-agent` + +and for the configured Gitea host only emits `username=$AGENT_LOGIN` + `password=`). `agentws new` wires this per worktree — it enables `extensions.worktreeConfig` on the repo once, then writes `user.name`, `user.email` and `credential.helper = ! credential` to the diff --git a/README.md b/README.md index 91c05b7..d15bcc0 100644 --- a/README.md +++ b/README.md @@ -1,11 +1,12 @@ # agent-tools Small Gitea-automation CLIs, shipped together in one RPM (`agent-tools`). They -act as the **`unkin-agent`** user by minting a scoped Gitea token from Vault, so -automated PRs, comments and pushes are attributed to the agent — not to whoever -happens to run the command. +act as an agent user (**`unkin-agent`** by default) by minting a scoped Gitea +token from Vault, so automated PRs, comments and pushes are attributed to the +agent — not to whoever happens to run the command. Set `AGENT_LOGIN` to act as a +different agent identity. -- **`agentpr`** — create pull requests and post PR comments as `unkin-agent`. +- **`agentpr`** — create pull requests and post PR comments as the agent user. - **`watchpr`** — poll one or more PRs and exit when one changes in a way worth acting on. - **`agentws`** — manage per-branch git worktrees for `unkin-agent`, cloning @@ -16,8 +17,9 @@ happens to run the command. ## How it gets a token On first use each tool performs a Vault AppRole login (`role_id` only, no -`secret_id`), then reads `gitea/creds/unkin-agent` to obtain a short-lived Gitea -token, cached in-process for the run. +`secret_id`), then reads `gitea/creds/$AGENT_LOGIN` — or `GITEA_CREDS_PATH` when +set — to obtain a short-lived Gitea token, cached in-process for the run. With +neither variable set that is `gitea/creds/unkin-agent`, as before. Everything is configured by environment variables, all with defaults: @@ -26,7 +28,8 @@ Everything is configured by environment variables, all with defaults: | `VAULT_ADDR` | `https://vault.service.consul:8200` | Vault/OpenBao address | | `AGENT_APPROLE_ROLE_ID` | built-in default | AppRole role_id (overridable) | | `GITEA_URL` | `https://git.unkin.net` | Gitea base URL | -| `AGENT_LOGIN` | `unkin-agent` | login whose comments `watchpr` ignores | +| `AGENT_LOGIN` | `unkin-agent` | agent identity: selects `gitea/creds/`, and the login whose comments `watchpr` ignores | +| `GITEA_CREDS_PATH` | `gitea/creds/$AGENT_LOGIN` | Vault path minting the Gitea token (wins over `AGENT_LOGIN`) | | `AGENTWS_SRC_ROOT` | `~/src/prodenv` | source-of-truth checkout root (`agentws`) | | `AGENTWS_ROOT` | `~/.cache/agentws` | worktree root (`agentws`) | | `AGENTWS_OWNER` | `unkin` | Gitea org that owns the repos (`agentws`) | @@ -35,7 +38,7 @@ Everything is configured by environment variables, all with defaults: ## agentpr ```bash -# Verify identity (should print: unkin-agent) +# Verify identity (prints the agent login, unkin-agent by default) agentpr whoami # Open a PR @@ -101,7 +104,7 @@ agentws rm ~/.cache/agentws/argocd-apps__benvin-my-change --delete-branch # Remove every managed worktree and prune each source repo agentws clean -# Print a fresh unkin-agent Gitea token +# Print a fresh Gitea token for the agent login agentws token ``` @@ -113,7 +116,7 @@ persists one in a remote URL or in git config. Instead it wires itself as an - `agentws token` prints a fresh token to stdout (handy for scripts). - `agentws credential get` speaks the git credential protocol on stdin and, for - the configured Gitea host only, emits `username=unkin-agent` + + the configured Gitea host only, emits `username=$AGENT_LOGIN` + `password=`. `agentws new` sets this up per worktree without touching the shared checkout: it diff --git a/cmd/agentpr/main.go b/cmd/agentpr/main.go index 7b12c0b..5f12952 100644 --- a/cmd/agentpr/main.go +++ b/cmd/agentpr/main.go @@ -1,7 +1,7 @@ -// Command agentpr manages Gitea pull requests and comments as the unkin-agent -// user. It obtains a scoped Gitea token from Vault (AppRole login, then reads -// gitea/creds/unkin-agent) so actions are attributed to the agent rather than -// to whoever runs the tool. +// Command agentpr manages Gitea pull requests and comments as an agent user. It +// obtains a scoped Gitea token from Vault (AppRole login, then reads +// gitea/creds/, or GITEA_CREDS_PATH when set) so actions are +// attributed to that agent rather than to whoever runs the tool. // // agentpr pr create --repo owner/repo --base main --head feature --title T --body B // agentpr pr comment --repo owner/repo --pr 12 --body "..." @@ -33,8 +33,8 @@ func main() { func newRootCmd() *cobra.Command { root := &cobra.Command{ Use: "agentpr", - Short: "Manage Gitea PRs and comments as the unkin-agent user.", - Long: "agentpr manages Gitea pull requests and comments as unkin-agent, using a\nGitea token minted from Vault (AppRole login + gitea/creds/unkin-agent).", + Short: "Manage Gitea PRs and comments as an agent user.", + Long: "agentpr manages Gitea pull requests and comments as an agent user, using a\nGitea token minted from Vault (AppRole login + gitea/creds/).\nSet AGENT_LOGIN to act as another agent identity, or GITEA_CREDS_PATH to name\nthe Vault creds path outright.", Version: version, SilenceUsage: true, } @@ -146,7 +146,7 @@ func newPRCommentCmd() *cobra.Command { func newWhoamiCmd() *cobra.Command { return &cobra.Command{ Use: "whoami", - Short: "Print the authenticated Gitea login (should be unkin-agent)", + Short: "Print the authenticated Gitea login (the identity PRs are opened as)", SilenceUsage: true, RunE: func(cmd *cobra.Command, args []string) error { c, err := client() diff --git a/internal/agent/client_test.go b/internal/agent/client_test.go index 20dac83..bade667 100644 --- a/internal/agent/client_test.go +++ b/internal/agent/client_test.go @@ -8,8 +8,9 @@ import ( "testing" ) -// fakeVault serves the AppRole login and gitea creds endpoints. -func fakeVault(t *testing.T, wantRoleID, giteaToken string) *httptest.Server { +// fakeVault serves the AppRole login and the gitea creds secret at credsPath +// only, so a read of any other path 404s. +func fakeVault(t *testing.T, wantRoleID, credsPath, giteaToken string) *httptest.Server { t.Helper() mux := http.NewServeMux() mux.HandleFunc("/v1/auth/approle/login", func(w http.ResponseWriter, r *http.Request) { @@ -26,7 +27,7 @@ func fakeVault(t *testing.T, wantRoleID, giteaToken string) *httptest.Server { } _, _ = io.WriteString(w, `{"auth":{"client_token":"s.vaulttoken"}}`) }) - mux.HandleFunc("/v1/"+GiteaCredsPath, func(w http.ResponseWriter, r *http.Request) { + mux.HandleFunc("/v1/"+credsPath, func(w http.ResponseWriter, r *http.Request) { if got := r.Header.Get("X-Vault-Token"); got != "s.vaulttoken" { t.Errorf("X-Vault-Token = %q, want s.vaulttoken", got) } @@ -36,10 +37,10 @@ func fakeVault(t *testing.T, wantRoleID, giteaToken string) *httptest.Server { } func TestFetchGiteaToken(t *testing.T) { - srv := fakeVault(t, "role-xyz", "gitea-abc") + srv := fakeVault(t, "role-xyz", "gitea/creds/unkin-agent", "gitea-abc") defer srv.Close() - tok, err := fetchGiteaToken(srv.URL, "role-xyz") + tok, err := fetchGiteaToken(srv.URL, "role-xyz", "gitea/creds/unkin-agent") if err != nil { t.Fatalf("fetchGiteaToken: %v", err) } @@ -57,7 +58,7 @@ func TestFetchGiteaTokenLoginError(t *testing.T) { srv := httptest.NewServer(mux) defer srv.Close() - if _, err := fetchGiteaToken(srv.URL, "role-xyz"); err == nil { + if _, err := fetchGiteaToken(srv.URL, "role-xyz", "gitea/creds/unkin-agent"); err == nil { t.Fatal("expected error on 403 login") } } diff --git a/internal/agent/token.go b/internal/agent/token.go index 9ebca7b..006c749 100644 --- a/internal/agent/token.go +++ b/internal/agent/token.go @@ -7,6 +7,7 @@ package agent import ( "os" + "strings" "sync" ) @@ -16,12 +17,14 @@ const ( // DefaultRoleID is the agent AppRole role_id used when AGENT_APPROLE_ROLE_ID // is unset. Login uses role_id only (no secret_id). DefaultRoleID = "ababbcd3-9c77-5c6a-be2d-287fce9214a6" - // GiteaCredsPath is the Vault path that mints a scoped Gitea token. - GiteaCredsPath = "gitea/creds/unkin-agent" + // GiteaCredsPrefix is the Vault gitea secrets-engine creds prefix; the agent + // login is appended to it to form the path that mints a scoped Gitea token. + GiteaCredsPrefix = "gitea/creds/" // DefaultGiteaURL is the Gitea base URL used when GITEA_URL is unset. DefaultGiteaURL = "https://git.unkin.net" - // DefaultAgentLogin is the Gitea login of the agent whose own comments are - // ignored by watchpr. Overridable via AGENT_LOGIN. + // DefaultAgentLogin is the Gitea login the tools act as: it selects the Vault + // creds path, sets the agentws git identity and is the login whose own + // comments watchpr ignores. Overridable via AGENT_LOGIN. DefaultAgentLogin = "unkin-agent" // DefaultAuthentikURL is the Authentik base URL used when AUTHENTIK_URL is // unset. identity.unkin.net has no DNS record; the k8s name is the real one. @@ -53,8 +56,8 @@ func GiteaURL() string { return DefaultGiteaURL } -// AgentLogin returns the login whose comments watchpr ignores (env AGENT_LOGIN -// or the default). +// AgentLogin returns the Gitea login the tools act as (env AGENT_LOGIN or the +// default). func AgentLogin() string { if v := os.Getenv("AGENT_LOGIN"); v != "" { return v @@ -62,6 +65,17 @@ func AgentLogin() string { return DefaultAgentLogin } +// GiteaCredsPath returns the Vault path that mints a scoped Gitea token: +// GITEA_CREDS_PATH when set, otherwise gitea/creds/. So a service +// running as its own identity only has to set AGENT_LOGIN. +func GiteaCredsPath() string { + // Trimmed because callers join this onto ".../v1/". + if v := strings.Trim(strings.TrimSpace(os.Getenv("GITEA_CREDS_PATH")), "/"); v != "" { + return v + } + return GiteaCredsPrefix + AgentLogin() +} + // AuthentikURL returns the configured Authentik base URL (env AUTHENTIK_URL or // the default). func AuthentikURL() string { @@ -81,18 +95,18 @@ var ( // and caching it in-process for the lifetime of the command. func GiteaToken() (string, error) { tokenOnce.Do(func() { - tokenValue, tokenErr = fetchGiteaToken(VaultAddr(), RoleID()) + tokenValue, tokenErr = fetchGiteaToken(VaultAddr(), RoleID(), GiteaCredsPath()) }) return tokenValue, tokenErr } -// fetchGiteaToken performs the AppRole login and reads the Gitea creds. It is -// separated from GiteaToken so tests can exercise it directly against an -// httptest server without touching the process-wide cache. -func fetchGiteaToken(vaultAddr, roleID string) (string, error) { +// fetchGiteaToken performs the AppRole login and reads the Gitea creds at +// credsPath. It is separated from GiteaToken so tests can exercise it directly +// against an httptest server without touching the process-wide cache. +func fetchGiteaToken(vaultAddr, roleID, credsPath string) (string, error) { clientToken, err := approleLogin(vaultAddr, roleID) if err != nil { return "", err } - return readGiteaCreds(vaultAddr, clientToken) + return readGiteaCreds(vaultAddr, clientToken, credsPath) } diff --git a/internal/agent/token_test.go b/internal/agent/token_test.go new file mode 100644 index 0000000..264e20a --- /dev/null +++ b/internal/agent/token_test.go @@ -0,0 +1,155 @@ +package agent + +import ( + "encoding/json" + "io" + "net/http" + "net/http/httptest" + "strings" + "sync" + "testing" +) + +func TestGiteaCredsPath(t *testing.T) { + tests := []struct { + name string + agentLogin string + credsPath string + want string + }{ + {"no env keeps the historical path", "", "", "gitea/creds/unkin-agent"}, + {"derived from AGENT_LOGIN", "repospawner", "", "gitea/creds/repospawner"}, + {"GITEA_CREDS_PATH beats AGENT_LOGIN", "repospawner", "gitea/creds/someone-else", "gitea/creds/someone-else"}, + {"GITEA_CREDS_PATH beats the default", "", "other-gitea/creds/bot", "other-gitea/creds/bot"}, + {"override is trimmed for joining onto /v1/", "", " /gitea/creds/bot/ ", "gitea/creds/bot"}, + {"blank override falls back to the login", "repospawner", " ", "gitea/creds/repospawner"}, + } + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + t.Setenv("AGENT_LOGIN", tt.agentLogin) + t.Setenv("GITEA_CREDS_PATH", tt.credsPath) + if got := GiteaCredsPath(); got != tt.want { + t.Errorf("GiteaCredsPath() = %q, want %q", got, tt.want) + } + }) + } +} + +// recordingVault serves the AppRole login plus any creds path under /v1/, +// recording which one was read so tests can assert the selected path. +type recordingVault struct { + mu sync.Mutex + credsPath string +} + +func (v *recordingVault) path() string { + v.mu.Lock() + defer v.mu.Unlock() + return v.credsPath +} + +// fakeEstate serves both Vault (/v1/...) and Gitea (/api/v1/...) from one +// server, so a test can drive the whole token-then-API flow. +func fakeEstate(t *testing.T, giteaToken, login string) (*httptest.Server, *recordingVault) { + t.Helper() + rec := &recordingVault{} + mux := http.NewServeMux() + mux.HandleFunc("/v1/auth/approle/login", func(w http.ResponseWriter, r *http.Request) { + _, _ = io.WriteString(w, `{"auth":{"client_token":"s.vaulttoken"}}`) + }) + mux.HandleFunc("/v1/", func(w http.ResponseWriter, r *http.Request) { + rec.mu.Lock() + rec.credsPath = strings.TrimPrefix(r.URL.Path, "/v1/") + rec.mu.Unlock() + _, _ = io.WriteString(w, `{"data":{"token":"`+giteaToken+`"}}`) + }) + mux.HandleFunc("/api/v1/user", func(w http.ResponseWriter, r *http.Request) { + if got := r.Header.Get("Authorization"); got != "token "+giteaToken { + t.Errorf("whoami auth header = %q, want token %s", got, giteaToken) + } + _, _ = io.WriteString(w, `{"login":"`+login+`","id":7}`) + }) + mux.HandleFunc("/api/v1/repos/unkin/repo/pulls", func(w http.ResponseWriter, r *http.Request) { + if got := r.Header.Get("Authorization"); got != "token "+giteaToken { + t.Errorf("create PR auth header = %q, want token %s", got, giteaToken) + } + var body CreatePROptions + _ = json.NewDecoder(r.Body).Decode(&body) + _, _ = io.WriteString(w, `{"number":12,"state":"open","html_url":"`+r.Host+`/pulls/12"}`) + }) + return httptest.NewServer(mux), rec +} + +// A service that sets AGENT_LOGIN must read its own creds path and act as its +// own Gitea identity for both whoami and PR creation. +func TestWhoamiAndPRUseSelectedCredsPath(t *testing.T) { + srv, rec := fakeEstate(t, "gitea-repospawner", "repospawner") + defer srv.Close() + + t.Setenv("AGENT_LOGIN", "repospawner") + t.Setenv("GITEA_CREDS_PATH", "") + t.Setenv("VAULT_ADDR", srv.URL) + t.Setenv("GITEA_URL", srv.URL) + + tok, err := fetchGiteaToken(VaultAddr(), RoleID(), GiteaCredsPath()) + if err != nil { + t.Fatalf("fetchGiteaToken: %v", err) + } + if got := rec.path(); got != "gitea/creds/repospawner" { + t.Errorf("vault read path = %q, want gitea/creds/repospawner", got) + } + if tok != "gitea-repospawner" { + t.Fatalf("token = %q, want gitea-repospawner", tok) + } + + c := NewGiteaClient(tok) + u, err := c.Whoami() + if err != nil { + t.Fatalf("Whoami: %v", err) + } + if u.Login != "repospawner" { + t.Errorf("whoami login = %q, want repospawner", u.Login) + } + + pr, err := c.CreatePR("unkin/repo", CreatePROptions{Base: "main", Head: "feature", Title: "T"}) + if err != nil { + t.Fatalf("CreatePR: %v", err) + } + if pr.Number != 12 { + t.Errorf("PR number = %d, want 12", pr.Number) + } +} + +// GITEA_CREDS_PATH must win even when AGENT_LOGIN names a different identity. +func TestCredsPathOverrideBeatsAgentLogin(t *testing.T) { + srv, rec := fakeEstate(t, "gitea-override", "someone-else") + defer srv.Close() + + t.Setenv("AGENT_LOGIN", "repospawner") + t.Setenv("GITEA_CREDS_PATH", "gitea/creds/someone-else") + t.Setenv("VAULT_ADDR", srv.URL) + + if _, err := fetchGiteaToken(VaultAddr(), RoleID(), GiteaCredsPath()); err != nil { + t.Fatalf("fetchGiteaToken: %v", err) + } + if got := rec.path(); got != "gitea/creds/someone-else" { + t.Errorf("vault read path = %q, want gitea/creds/someone-else", got) + } +} + +// With no env set the tools must still read the exact path they always did. +func TestCredsPathDefaultIsBackwardCompatible(t *testing.T) { + srv, rec := fakeEstate(t, "gitea-abc", "unkin-agent") + defer srv.Close() + + t.Setenv("AGENT_LOGIN", "") + t.Setenv("GITEA_CREDS_PATH", "") + t.Setenv("VAULT_ADDR", srv.URL) + + if _, err := fetchGiteaToken(VaultAddr(), RoleID(), GiteaCredsPath()); err != nil { + t.Fatalf("fetchGiteaToken: %v", err) + } + if got := rec.path(); got != "gitea/creds/unkin-agent" { + t.Errorf("vault read path = %q, want gitea/creds/unkin-agent", got) + } +} diff --git a/internal/agent/vault.go b/internal/agent/vault.go index 8fcd73b..844f97d 100644 --- a/internal/agent/vault.go +++ b/internal/agent/vault.go @@ -49,9 +49,10 @@ func approleLogin(vaultAddr, roleID string) (string, error) { return out.Auth.ClientToken, nil } -// readGiteaCreds reads the Gitea creds secret and returns the token field. -func readGiteaCreds(vaultAddr, clientToken string) (string, error) { - url := strings.TrimRight(vaultAddr, "/") + "/v1/" + GiteaCredsPath +// readGiteaCreds reads the Gitea creds secret at credsPath and returns the +// token field. +func readGiteaCreds(vaultAddr, clientToken, credsPath string) (string, error) { + url := strings.TrimRight(vaultAddr, "/") + "/v1/" + credsPath req, err := http.NewRequest(http.MethodGet, url, nil) if err != nil { return "", err @@ -60,12 +61,12 @@ func readGiteaCreds(vaultAddr, clientToken string) (string, error) { resp, err := httpClient.Do(req) if err != nil { - return "", fmt.Errorf("vault read %s: %w", GiteaCredsPath, err) + return "", fmt.Errorf("vault read %s: %w", credsPath, err) } defer func() { _ = resp.Body.Close() }() data, _ := io.ReadAll(resp.Body) if resp.StatusCode != http.StatusOK { - return "", fmt.Errorf("vault read %s: HTTP %d: %s", GiteaCredsPath, resp.StatusCode, strings.TrimSpace(string(data))) + return "", fmt.Errorf("vault read %s: HTTP %d: %s", credsPath, resp.StatusCode, strings.TrimSpace(string(data))) } var out struct { @@ -74,10 +75,10 @@ func readGiteaCreds(vaultAddr, clientToken string) (string, error) { } `json:"data"` } if err := json.Unmarshal(data, &out); err != nil { - return "", fmt.Errorf("vault read %s: decoding response: %w", GiteaCredsPath, err) + return "", fmt.Errorf("vault read %s: decoding response: %w", credsPath, err) } if out.Data.Token == "" { - return "", fmt.Errorf("vault read %s: no token field in secret", GiteaCredsPath) + return "", fmt.Errorf("vault read %s: no token field in secret", credsPath) } return out.Data.Token, nil }