From 29b048e06631c8471f4567f61640cdb348ac5bfb Mon Sep 17 00:00:00 2001 From: Eric Liu Date: Mon, 7 Sep 2026 20:52:36 -0700 Subject: [PATCH 1/2] chore(plugin): release v0.1.3 --- plugin/pyproject.toml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugin/pyproject.toml b/plugin/pyproject.toml index b641911..3fcd6f7 100644 --- a/plugin/pyproject.toml +++ b/plugin/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "hatchling.build" [project] name = "hermes-meshtastic" -version = "0.1.2" +version = "0.1.3" description = "Meshtastic LoRa mesh gateway adapter plugin for Hermes Agent" readme = "README.md" requires-python = ">=3.10" From b8e9b659954b6ea517fefe9b0f576a16acdec2a5 Mon Sep 17 00:00:00 2001 From: Eric Liu Date: Mon, 7 Sep 2026 21:01:34 -0700 Subject: [PATCH 2/2] fix(ci): forward auth token across http->https redirect on release publish curl drops the Authorization header when -L follows Gitea's 308 redirect from http server_url to https, so the API replied 'token is required' and publish failed with no release id. Add --location-trusted to every publish curl. --- .gitea/workflows/release.yaml | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/.gitea/workflows/release.yaml b/.gitea/workflows/release.yaml index ec4dca0..29bf32c 100644 --- a/.gitea/workflows/release.yaml +++ b/.gitea/workflows/release.yaml @@ -83,17 +83,19 @@ jobs: tar_file=$(ls plugin/dist/*.tar.gz | head -n 1) api_url="${{ github.server_url }}/api/v1/repos/${{ github.repository }}" - # server_url may be http while Gitea redirects (308) to https: - # curl needs -L or the POST returns an empty body. Release may also - # already exist (retried run) — reuse it instead of failing. + # server_url is http and Gitea answers with a 308 redirect to https. + # curl needs -L to follow, AND --location-trusted: without it curl + # drops the Authorization header on the scheme-changing redirect and + # Gitea replies "token is required". Release may already exist + # (retried run) — reuse it instead of failing. fetch_id() { python3 -c "import json,sys;print(json.load(sys.stdin).get('id') or '')" 2>/dev/null; } - response=$(curl -s -k -L -H "Authorization: token $GITEA_TOKEN" \ + response=$(curl -s -k -L --location-trusted -H "Authorization: token $GITEA_TOKEN" \ "$api_url/releases/tags/$tag_name") release_id=$(printf '%s' "$response" | fetch_id) if [ -z "$release_id" ]; then - response=$(curl -s -k -L -X POST "$api_url/releases" \ + response=$(curl -s -k -L --location-trusted -X POST "$api_url/releases" \ -H "Authorization: token $GITEA_TOKEN" \ -H "Content-Type: application/json" \ -d "{\"tag_name\": \"$tag_name\", \"name\": \"$tag_name\", \"body\": \"Release $tag_name for hermes-meshtastic plugin\"}") @@ -101,11 +103,11 @@ jobs: fi if [ -n "$release_id" ]; then - curl -s -k -L -X POST "$api_url/releases/$release_id/assets?name=$(basename "$wheel_file")" \ + curl -s -k -L --location-trusted -X POST "$api_url/releases/$release_id/assets?name=$(basename "$wheel_file")" \ -H "Authorization: token $GITEA_TOKEN" \ -H "Content-Type: application/octet-stream" \ --data-binary "@$wheel_file" - curl -s -k -L -X POST "$api_url/releases/$release_id/assets?name=$(basename "$tar_file")" \ + curl -s -k -L --location-trusted -X POST "$api_url/releases/$release_id/assets?name=$(basename "$tar_file")" \ -H "Authorization: token $GITEA_TOKEN" \ -H "Content-Type: application/octet-stream" \ --data-binary "@$tar_file"