Found on the actual first deployment: /api/v1/healthz proves the process is
up, but says nothing about whether login actually works, because the
session cookie is set with Secure in production. Test through a plain-HTTP
address (an IP, a bare port, skipping the reverse proxy) and /auth/login
still returns 200 with a valid body — the cookie is just silently dropped by
the client, so the very next request looks unauthenticated. From a browser
this looks exactly like "I logged in and it bounced me straight back to the
login screen," with no error anywhere to point at.
scripts/smoke-test.sh does the real round trip a browser does: login,
confirm a session cookie was actually stored (not just sent), then an
authenticated follow-up request confirming it succeeds and returns the
right account. Verified it actually catches what it's meant to catch before
committing: ran it against a throwaway account over plain HTTP against a
production-mode container and got the expected FAIL with a diagnostic
pointing at the Secure-cookie mismatch, then confirmed PASS once the
container's VELODROME_ENVIRONMENT was (inadvertently, in this case)
development instead.
Documented in deploy/README.md as the real post-deploy check, replacing
"hit /healthz and eyeball it" for anything involving auth.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01R2ZKeWkZV7ehf7fivrAkkG
An exported GITEA_TOKEN only exists in the shell that exported it, so
tooling invoked from elsewhere could not find it. Resolve in order:
$GITEA_TOKEN, ~/.config/gitea/token, then the macOS Keychain — so the
token can live somewhere durable and non-world-readable instead of a
plaintext dotfile.
Also factors the API call and repo coordinates into scripts/lib/gitea.sh
so pr.sh and review.sh stop duplicating them, and adds
`review.sh --list` for enumerating open PRs.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Prepares the repo for parallel agent work. No application code.
- CLAUDE.md: conventions, branch naming, and the six non-negotiable
invariants from the design (immutable raw bytes, no stored odometers,
SI integers, dual-layer user isolation, secret containment, single
ingestion path). Also records a model-allocation policy: the
orchestrator runs Opus 5, workers default to Sonnet, and Opus is
reserved for review plus the areas where a mistake is silent and
expensive (ingest, wear SQL, auth/RLS, the Bryton protocol client).
And the Gitea Actions gotchas, so nobody rediscovers them:
GITEA_TOKEN cannot push to the container registry, jobs.*.environment
is ignored, and cron needs a workflow_dispatch pair.
- CONTRIBUTING.md: day-to-day flow, worktrees for parallel branches,
review expectations.
- .gitea/workflows/ci.yml: repo hygiene (branch naming, secret scan,
no ride data in git), plus API/web/migration jobs that guard on whether
the code exists yet, so CI is meaningful now and grows into the real
thing rather than being rewritten.
- .gitea/PULL_REQUEST_TEMPLATE.md: forces an honest "how this was
verified" and an invariant checklist.
- scripts/pr.sh, scripts/review.sh: open and inspect PRs via the Gitea API.
- Directory scaffold with placeholder READMEs.
Agents open PRs; humans merge them.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>