Sitelet https://github.com/msgwing/ZeroSMTP/pull/231
Skip to content

feat(report): ruch przez wlasny token, zeby firma przestala pracowac na slepo - #231

Merged
msgwing merged 1 commit into
mainfrom
traffic-feedback-loop
Aug 23, 2026
Merged

msgwing merged 1 commit into
mainfrom
traffic-feedback-loop

Conversation

@msgwing

@msgwing msgwing commented Aug 23, 2026

Copy link
Copy Markdown
Owner

Raport od zawsze mówił, że endpointy ruchu są poza zasięgiem. Są poza zasięgiem tokena Actions — i to się z czasem skróciło do „niemożliwe", przez co nikt się tym nie zajął przez tygodnie.

Zweryfikowane w dokumentacji GitHuba, nie z pamięci: trzy endpointy ruchu wymagają tokena drobnoziarnistego z uprawnieniem „Administration" → Read-only. To token, który człowiek tworzy raz.

Dlaczego osobnym torem, a nie podmianą

Czyta go zwykły fetch z własnym poświadczeniem, a nie przez ustawienie go jako github-token tego kroku. Ta druga droga jest oczywistym skrótem i zepsułaby raport: każdy zapis w kroku działałby wtedy jako właściciel, a GitHub nie powiadamia aktora, który sam wykonał akcję — raport po cichu przestałby mailować jedyną osobę, dla której jest pisany.

To czerwona linia nr 7 i uszanowanie jej nie kosztuje tu nic.

Brak sekretu zostaje stanem obsługiwanym

Bez niego raport drukuje to, co drukował dotąd — tyle że mówi teraz, którego sekretu brakuje i ile to kosztuje.

I to jest właściwy powód, dla którego to ma znaczenie: dziś stanęło 14 stron błędów, zaindeksowanych URL-i jest 48, a między jednym ręcznym sprawdzeniem a drugim nikt nie wie, które z nich przynoszą choć jednego człowieka.

Program zasięgowy bez pętli zwrotnej to zgadywanie powtarzane wedle harmonogramu.

…s working blind

The report has always said the traffic endpoints were out of reach. They are
out of reach for the Actions token specifically, and that got shortened over
time into "impossible", which is why nothing was done about it for weeks.

Verified against GitHub's documentation rather than recalled: the three traffic
endpoints need a fine-grained token carrying "Administration" repository
permissions, read. That is a token a person creates once.

It is read through a plain fetch with its own credential, not by setting it as
this step's github-token. Setting it there would be the obvious shortcut and it
would break the report: every write in the step would then act as the owner,
and GitHub does not notify the actor who performed an action, so the report
would quietly stop mailing the one person it is written for. That is red line 7
and it costs nothing to respect here.

Absent stays a supported state. Without the secret the report prints what it
printed before, now saying which secret is missing and what it costs: without
it the company builds pages without being able to see which ones bring anybody.

That is the actual reason this matters. Fourteen error pages went up today and
forty-eight URLs are indexed, and between one manual check and the next nobody
can tell which of them earn a visitor. A reach programme with no feedback loop
is a guess repeated on a schedule.
@msgwing
msgwing enabled auto-merge August 23, 2026 09:20
@github-actions github-actions Bot added the ci label Aug 23, 2026
@msgwing
msgwing merged commit f534204 into main Aug 23, 2026
35 of 36 checks passed
@msgwing
msgwing deleted the traffic-feedback-loop branch August 23, 2026 09:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant