mirror of
https://github.com/MAKS-IT-COM/maksit-gitea-cursor.git
synced 2026-09-29 20:48:10 +02:00
1.4 KiB
1.4 KiB
Security policy
This plugin talks to your Gitea instance with your personal access token. Treat the token like a password.
Report a vulnerability
Email security-reports@cursor.com if the issue is in how Cursor loads plugins.
For this repository, open a private security advisory on MAKS-IT-COM/maksit-gitea-cursor, or email maksym.sadovnychyy@gmail.com. Do not file a public issue that includes tokens, secrets, or a working exploit.
What this plugin does
- Sends
Authorization: token …only to{GITEA_URL}/api/v1/.... - Rejects absolute URLs,
..path segments, and redirects that leave that API prefix. - Requires HTTPS except for localhost (override with
GITEA_ALLOW_HTTP=trueon a trusted network only). - Defaults to a curated toolset. Admin APIs, raw
gitea_request, Actions secrets, runner tokens, and PAT create/delete are off until you set the matching env flag.
What you should do
- Create a Gitea token with the minimum scopes you need. Do not grant site-admin unless you also set
GITEA_ENABLE_ADMIN=trueand understand the risk. - Prefer
GITEA_READ_ONLY=truefor review-only agents. - Never commit
.envfiles or paste tokens into issues, skills, or chat logs. - Trust self-signed certificates in the OS trust store. This plugin does not disable TLS verification.