Go to file
Lunny Xiao f3bdcc58af
Fix OAuth2 authorization code expiry and reuse handling (#36797)
- set OAuth2 authorization code `ValidUntil` on creation and add expiry
checks during exchange
- return a specific error when codes are invalidated twice to prevent
concurrent reuse
- add unit tests covering validity timestamps, expiration, and double
invalidation

---
Generate by a coding agent with Codex 5.2

---------

Signed-off-by: Lunny Xiao <xiaolunwen@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-03-06 05:00:44 +00:00
.devcontainer Update JS and PY deps (#36383) 2026-01-16 11:00:16 +00:00
.gitea Update demo site location from try.gitea.io -> demo.gitea.com (#31054) 2024-05-27 15:05:12 +00:00
.github Enable docker layer caching for `dry-run` and `nightly` container builds (#36738) 2026-03-01 21:18:46 +00:00
assets Mark unused&immature activitypub as "not implemented" (#36789) 2026-03-01 12:59:49 +00:00
build Replace `google/go-licenses` with custom generation (#36575) 2026-02-18 04:13:26 +00:00
cmd Fix bug when pushing mirror with wiki (#36795) 2026-03-02 20:58:07 +00:00
contrib Intorduce "config edit-ini" sub command to help maintaining INI config file (#35735) 2025-10-25 10:54:55 +08:00
custom/conf Add `never` option to `PUBLIC_URL_DETECTION` configuration (#36785) 2026-03-01 18:33:47 +00:00
docker Intorduce "config edit-ini" sub command to help maintaining INI config file (#35735) 2025-10-25 10:54:55 +08:00
models Fix OAuth2 authorization code expiry and reuse handling (#36797) 2026-03-06 05:00:44 +00:00
modules Fix forwarded proto handling for public URL detection (#36810) 2026-03-06 00:31:52 +08:00
options build(deps): update material-icon-theme v5.32.0 (#36832) 2026-03-05 11:51:26 -08:00
public Update JS deps (#36656) 2026-02-17 19:35:37 +01:00
routers Fix OAuth2 authorization code expiry and reuse handling (#36797) 2026-03-06 05:00:44 +00:00
services Fix non-admins unable to automerge PRs from forks (#36833) 2026-03-06 00:03:12 +00:00
snap add pnpm to Snapcraft (#35778) 2025-10-29 19:34:40 +01:00
templates fix(repo): unify DEFAULT_SHOW_FULL_NAME output in templates and dropdown (#36597) 2026-03-04 21:23:17 +08:00
tests Fix org permission API visibility checks for hidden members and private orgs (#36798) 2026-03-05 20:32:15 -08:00
tools Rework e2e tests (#36634) 2026-02-20 16:26:47 -08:00
web_src fix(repo): unify DEFAULT_SHOW_FULL_NAME output in templates and dropdown (#36597) 2026-03-04 21:23:17 +08:00
.air.toml Update JS deps, fix deprecations (#36040) 2025-11-27 23:58:10 +00:00
.changelog.yml Update .changelog file to add performance label group (#33472) 2025-02-02 06:40:39 +00:00
.dockerignore Add cache to container build (#35697) 2025-11-02 09:42:25 +00:00
.editorconfig Allow empty commit when merging pull request with squash style (#35989) 2025-11-22 06:02:25 +00:00
.envrc Enable direnv (#31672) 2024-07-23 12:07:41 +00:00
.gitattributes Add ability for local makefile with personal customizations that wouldnt affect remote repo (#35836) 2025-11-08 20:23:55 +00:00
.gitignore Rework e2e tests (#36634) 2026-02-20 16:26:47 -08:00
.gitpod.yml Remove sqlite-viewer and using database client (#31223) 2024-06-03 10:41:29 +00:00
.golangci.yml Mark unused&immature activitypub as "not implemented" (#36789) 2026-03-01 12:59:49 +00:00
.ignore Clean bindata (#34728) 2025-06-16 12:03:51 +00:00
.mailmap [chore] add git mailmap for proper attribution of authorship (#33612) 2025-02-16 20:49:28 +08:00
.markdownlint.yaml Enable markdownlint `no-trailing-punctuation` and `no-blanks-blockquote` (#29214) 2024-02-17 13:18:05 +00:00
.npmrc Switch to pnpm (#35274) 2025-09-04 01:17:14 +00:00
.spectral.yaml
.yamllint.yaml Move jobparser from act repository to Gitea (#36699) 2026-02-22 19:33:01 +00:00
AGENTS.md Update AGENTS.md instructions (#36627) 2026-02-14 18:11:13 +01:00
BSDmakefile Fix build errors on BSD (in BSDMakefile) (#27594) 2023-10-13 15:38:27 +00:00
CHANGELOG-archived.md Fix changelog (main) (#30582) 2024-04-19 06:08:30 +00:00
CHANGELOG.md Front port changelog for 1.25.4 (#36432) 2026-01-23 15:31:01 +00:00
CLAUDE.md Improve timeline entries for WIP prefix changes in pull requests (#36518) 2026-02-05 05:57:08 +00:00
CODE_OF_CONDUCT.md Fixed minor typos in two files #HSFDPMUW (#34944) 2025-07-06 09:27:26 -07:00
CONTRIBUTING.md Add AI Contribution Policy to CONTRIBUTING.md (#36651) 2026-02-20 20:46:40 -08:00
DCO
Dockerfile Fix multi-arch Docker build SIGILL by splitting frontend stage (#36646) 2026-02-17 08:25:07 +00:00
Dockerfile.rootless Fix multi-arch Docker build SIGILL by splitting frontend stage (#36646) 2026-02-17 08:25:07 +00:00
LICENSE
MAINTAINERS apply as maintainer (#35424) 2025-09-06 09:56:18 -07:00
Makefile Filter out untracked files from spellchecking (#36756) 2026-02-26 23:06:31 +00:00
README.md Switch to pnpm (#35274) 2025-09-04 01:17:14 +00:00
README.zh-cn.md Remove `node-check` and `go-check`, support node prerelease versions (#36382) 2026-01-22 09:30:02 +01:00
README.zh-tw.md Remove `node-check` and `go-check`, support node prerelease versions (#36382) 2026-01-22 09:30:02 +01:00
SECURITY.md Upgrade security public key (#34956) 2025-07-05 10:11:41 -04:00
crowdin.yml Convert locale files from ini to json format (#35489) 2025-12-19 09:50:48 -08:00
eslint.config.ts Add keyboard shortcuts for repository file and code search (#36416) 2026-02-23 17:20:56 +08:00
eslint.json.config.ts Add JSON linting (#36192) 2025-12-19 06:27:21 +00:00
flake.lock Update Nix flake (#36787) 2026-03-01 07:56:23 +00:00
flake.nix Port away from `flake-utils` (#35675) 2025-11-04 16:28:59 +00:00
go.mod upgrade to github.com/cloudflare/circl 1.6.3, svgo 4.0.1, markdownlint-cli 0.48.0 (#36837) 2026-03-05 13:42:47 -08:00
go.sum upgrade to github.com/cloudflare/circl 1.6.3, svgo 4.0.1, markdownlint-cli 0.48.0 (#36837) 2026-03-05 13:42:47 -08:00
main.go Clean up Makefile, tests and legacy code (#36638) 2026-02-19 01:23:32 +00:00
main_timezones.go add `timetzdata` build tag to binary releases (#33463) 2025-02-05 04:17:08 +00:00
package.json upgrade to github.com/cloudflare/circl 1.6.3, svgo 4.0.1, markdownlint-cli 0.48.0 (#36837) 2026-03-05 13:42:47 -08:00
playwright.config.ts Rework e2e tests (#36634) 2026-02-20 16:26:47 -08:00
pnpm-lock.yaml upgrade to github.com/cloudflare/circl 1.6.3, svgo 4.0.1, markdownlint-cli 0.48.0 (#36837) 2026-03-05 13:42:47 -08:00
pyproject.toml Update JS and PY deps (#36383) 2026-01-16 11:00:16 +00:00
stylelint.config.js Move Fomantic dropdown CSS to custom module (#36530) 2026-02-27 16:45:10 +00:00
tailwind.config.ts Add code editor setting dropdowns (#36534) 2026-02-12 03:55:46 +08:00
tsconfig.json Clean up Makefile, tests and legacy code (#36638) 2026-02-19 01:23:32 +00:00
types.d.ts Remove and forbid `@ts-expect-error` (#36513) 2026-02-02 01:00:34 +08:00
updates.config.ts Update JS and PY deps (#36576) 2026-02-10 15:39:17 +00:00
uv.lock Update JS and PY deps (#36708) 2026-02-22 19:56:45 +00:00
vitest.config.ts Update JS dependencies, adjust webpack config, misc fixes (#36431) 2026-01-24 07:35:46 +00:00
webpack.config.ts Use `relative-time` to render absolute dates (#36238) 2026-02-16 10:58:04 +00:00

README.md

Gitea

Contribute with Gitpod

繁體中文 | 简体中文

Purpose

The goal of this project is to make the easiest, fastest, and most painless way of setting up a self-hosted Git service.

As Gitea is written in Go, it works across all the platforms and architectures that are supported by Go, including Linux, macOS, and Windows on x86, amd64, ARM and PowerPC architectures. This project has been forked from Gogs since November of 2016, but a lot has changed.

For online demonstrations, you can visit demo.gitea.com.

For accessing free Gitea service (with a limited number of repositories), you can visit gitea.com.

To quickly deploy your own dedicated Gitea instance on Gitea Cloud, you can start a free trial at cloud.gitea.com.

Documentation

You can find comprehensive documentation on our official documentation website.

It includes installation, administration, usage, development, contributing guides, and more to help you get started and explore all features effectively.

If you have any suggestions or would like to contribute to it, you can visit the documentation repository

Building

From the root of the source tree, run:

TAGS="bindata" make build

or if SQLite support is required:

TAGS="bindata sqlite sqlite_unlock_notify" make build

The build target is split into two sub-targets:

Internet connectivity is required to download the go and npm modules. When building from the official source tarballs which include pre-built frontend files, the frontend target will not be triggered, making it possible to build without Node.js.

More info: https://docs.gitea.com/installation/install-from-source

Using

After building, a binary file named gitea will be generated in the root of the source tree by default. To run it, use:

./gitea web

[!NOTE] If you're interested in using our APIs, we have experimental support with documentation.

Contributing

Expected workflow is: Fork -> Patch -> Push -> Pull Request

[!NOTE]

  1. YOU MUST READ THE CONTRIBUTORS GUIDE BEFORE STARTING TO WORK ON A PULL REQUEST.
  2. If you have found a vulnerability in the project, please write privately to security@gitea.io. Thanks!

Translating

Crowdin

Translations are done through Crowdin. If you want to translate to a new language, ask one of the managers in the Crowdin project to add a new language there.

You can also just create an issue for adding a language or ask on Discord on the #translation channel. If you need context or find some translation issues, you can leave a comment on the string or ask on Discord. For general translation questions there is a section in the docs. Currently a bit empty, but we hope to fill it as questions pop up.

Get more information from documentation.

Official and Third-Party Projects

We provide an official go-sdk, a CLI tool called tea and an action runner for Gitea Action.

We maintain a list of Gitea-related projects at gitea/awesome-gitea, where you can discover more third-party projects, including SDKs, plugins, themes, and more.

Communication

If you have questions that are not covered by the documentation, you can get in contact with us on our Discord server or create a post in the discourse forum.

Authors

Backers

Thank you to all our backers! 🙏 [Become a backer]

Sponsors

Support this project by becoming a sponsor. Your logo will show up here with a link to your website. [Become a sponsor]

FAQ

How do you pronounce Gitea?

Gitea is pronounced /ɡɪti:/ as in "gi-tea" with a hard g.

Why is this not hosted on a Gitea instance?

We're working on it.

Where can I find the security patches?

In the release log or the change log, search for the keyword SECURITY to find the security patches.

License

This project is licensed under the MIT License. See the LICENSE file for the full license text.

Further information

Looking for an overview of the interface? Check it out!

Login/Register Page

Login Register

User Dashboard

Home Issues Pull Requests Milestones

User Profile

Profile

Explore

Repos Users Orgs

Repository

Home Commits Branches Labels Milestones Releases Tags

Repository Issue

List Issue

Repository Pull Requests

List Pull Request File Commits

Repository Actions

List Details

Repository Activity

Activity Contributors Code Frequency Recent Commits

Organization

Home