From 6939e0cbbc9bb28b4e7bcb59e63ca59204c540e0 Mon Sep 17 00:00:00 2001 From: Dai Ha Date: Sat, 15 Aug 2026 18:20:55 +0200 Subject: [PATCH] CB-592: the tracked opencode.json must name the worker forge token, not the admin one MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Operator's rule, 2026-08-15: only the leader and architects may use GITEA_ACCESS_TOKEN; everyone else uses WORKER_GITEA_TOKEN. opencode.json is TRACKED, so it ships in every worker worktree, and it mounted the gitea MCP with {env:GITEA_ACCESS_TOKEN}. A live probe confirmed that variable actually resolves inside a member: herdr spawns each pane from its own login-shell environment and layers the launcher's map on top, so a member sees 108 variables rather than the small explicit set baseEnv appears to build. That gave an opencode member admin forge TOOLS — enough to merge its own PR, which both CLAUDE.md and the member contract forbid. This is the narrow half of the fix: it removes the tooling. The admin token is still present as a string in every member's environment, which is the real defect and is tracked as CB-592 (gitea #77) — that fix belongs in the launcher, in one place, not per-profile in bridged.yaml where a sixth profile would silently reopen it. .mcp.json keeps GITEA_ACCESS_TOKEN and is correct to: it is skip-worktree, the primary's own local copy, and the primary is the lead. That is the pattern this change follows — the shared tracked file grants least privilege, and anything needing more overrides locally. --- opencode.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/opencode.json b/opencode.json index eb11b2c..221a43a 100644 --- a/opencode.json +++ b/opencode.json @@ -26,7 +26,7 @@ ], "enabled": true, "environment": { - "GITEA_ACCESS_TOKEN": "{env:GITEA_ACCESS_TOKEN}", + "GITEA_ACCESS_TOKEN": "{env:WORKER_GITEA_TOKEN}", "GITEA_HOST": "{env:GITEA_HOST}" } }