6939e0cbbc
Operator's rule, 2026-08-15: only the leader and architects may use GITEA_ACCESS_TOKEN;
everyone else uses WORKER_GITEA_TOKEN.
opencode.json is TRACKED, so it ships in every worker worktree, and it mounted the gitea
MCP with {env:GITEA_ACCESS_TOKEN}. A live probe confirmed that variable actually resolves
inside a member: herdr spawns each pane from its own login-shell environment and layers
the launcher's map on top, so a member sees 108 variables rather than the small explicit
set baseEnv appears to build. That gave an opencode member admin forge TOOLS — enough to
merge its own PR, which both CLAUDE.md and the member contract forbid.
This is the narrow half of the fix: it removes the tooling. The admin token is still
present as a string in every member's environment, which is the real defect and is
tracked as CB-592 (gitea #77) — that fix belongs in the launcher, in one place, not
per-profile in bridged.yaml where a sixth profile would silently reopen it.
.mcp.json keeps GITEA_ACCESS_TOKEN and is correct to: it is skip-worktree, the primary's
own local copy, and the primary is the lead. That is the pattern this change follows —
the shared tracked file grants least privilege, and anything needing more overrides
locally.
35 lines
691 B
JSON
35 lines
691 B
JSON
{
|
|
"$schema": "https://opencode.ai/config.json",
|
|
"instructions": [
|
|
"CLAUDE.md"
|
|
],
|
|
"mcp": {
|
|
"bridged": {
|
|
"type": "remote",
|
|
"url": "http://127.0.0.1:8765/mcp",
|
|
"enabled": true
|
|
},
|
|
"context7": {
|
|
"type": "remote",
|
|
"url": "https://ct7.ltms.dev/mcp",
|
|
"enabled": true,
|
|
"headers": {
|
|
"Authorization": "Bearer {env:CONTEXT7_TOKEN}"
|
|
}
|
|
},
|
|
"gitea": {
|
|
"type": "local",
|
|
"command": [
|
|
"gitea-mcp",
|
|
"-t",
|
|
"stdio"
|
|
],
|
|
"enabled": true,
|
|
"environment": {
|
|
"GITEA_ACCESS_TOKEN": "{env:WORKER_GITEA_TOKEN}",
|
|
"GITEA_HOST": "{env:GITEA_HOST}"
|
|
}
|
|
}
|
|
}
|
|
}
|