# [Bug] Missing Gitea API Token Prevents Student Repository Provisioning #1161

Open
opened 2026-10-02 01:51:13 +00:00 by enjin2310 · 1 comment

Summary

In the SpikerSoft Staff → Issues section, multiple entries show failed provisioning of student repositories. The system attempts to create a GiteaStudentRepository for each new user account but fails due to missing or invalid Gitea API credentials. This prevents automatic repository creation for coding lessons.

Issue Description

When a new user account is created, the system should automatically generate a linked Gitea repository for coding lessons. However, the provisioning process fails with the following error:

Error: Gitea AccessToken or HTTPS username/password must be configured to provision student repositories.

This indicates that the system lacks a valid Gitea AccessToken or proper authentication configuration for repository management.

Environment

Property Value
Application SpikerSoft Admin Panel
Module Staff → Issues
Environment Production
Browser Firefox / Chrome
Operating System Windows 11
Version v2026.10.02a
Device Desktop

Preconditions

  • Gitea integration is enabled in the system.
  • New user accounts are created and expected to receive associated repositories.

Steps to Reproduce

  1. Create a new user account in SpikerSoft.
  2. Observe the automatic repository provisioning process.
  3. Check the Staff → Issues section.
  4. Note the failed entries with the error message above.

Expected Result

Each new user should have a Gitea repository automatically created and linked to their profile for coding lessons.

Actual Result

  • Repository creation fails for all new users.
  • Error message indicates missing or invalid Gitea API credentials.
  • Manual retry does not resolve the issue.

Evidence

  • Screenshot shows multiple failed GiteaStudentRepository entries with identical error messages.
  • Each entry includes user details and timestamps confirming repeated failures.

Impact

  • Prevents students from accessing their coding lesson repositories.
  • Breaks integration between SpikerSoft and Gitea.
  • Requires manual intervention for repository setup.

Frequency

Always

Reproducibility

100%

Severity

High

Suggested Fix

  • Configure a valid Gitea AccessToken in the system’s integration settings.
  • Verify HTTPS authentication credentials for repository provisioning.
  • Implement error handling to alert administrators when token validity expires.
  • Test repository creation workflow after credentials update to confirm resolution.
## Summary In the **SpikerSoft Staff → Issues** section, multiple entries show failed provisioning of student repositories. The system attempts to create a **GiteaStudentRepository** for each new user account but fails due to missing or invalid Gitea API credentials. This prevents automatic repository creation for coding lessons. ## Issue Description When a new user account is created, the system should automatically generate a linked **Gitea repository** for coding lessons. However, the provisioning process fails with the following error: > **Error: Gitea AccessToken or HTTPS username/password must be configured to provision student repositories.** This indicates that the system lacks a valid **Gitea AccessToken** or proper authentication configuration for repository management. ## Environment | Property | Value | |-----------|--------| | Application | SpikerSoft Admin Panel | | Module | Staff → Issues | | Environment | Production | | Browser | Firefox / Chrome | | Operating System | Windows 11 | | Version | v2026.10.02a | | Device | Desktop | ## Preconditions - Gitea integration is enabled in the system. - New user accounts are created and expected to receive associated repositories. ## Steps to Reproduce 1. Create a new user account in **SpikerSoft**. 2. Observe the automatic repository provisioning process. 3. Check the **Staff → Issues** section. 4. Note the failed entries with the error message above. ## Expected Result Each new user should have a **Gitea repository** automatically created and linked to their profile for coding lessons. ## Actual Result - Repository creation fails for all new users. - Error message indicates missing or invalid Gitea API credentials. - Manual retry does not resolve the issue. ## Evidence - Screenshot shows multiple failed **GiteaStudentRepository** entries with identical error messages. - Each entry includes user details and timestamps confirming repeated failures. ## Impact - Prevents students from accessing their coding lesson repositories. - Breaks integration between SpikerSoft and Gitea. - Requires manual intervention for repository setup. ## Frequency Always ## Reproducibility 100% ## Severity High ## Suggested Fix - Configure a valid **Gitea AccessToken** in the system’s integration settings. - Verify HTTPS authentication credentials for repository provisioning. - Implement error handling to alert administrators when token validity expires. - Test repository creation workflow after credentials update to confirm resolution.
Owner

Confirmed — thanks for the clear report and for including the exact error text. It pointed straight at the cause.

What was wrong: when a new user's profile is first created (or a child account is approved), the API tries to create that student's private Gitea repository for coding lessons. To call Gitea it needs credentials: an access token (Gitea:AccessToken) or a username and password. Production had the Gitea address and organization configured, but the token was blank. So every signup stopped early and filed a "needs attention" item in Staff → Issues — one per new account, exactly as you saw.

The code did what it was designed to do when a setting is missing. The real gap was configuration, plus a bit of noise.

What's done

  • spikerj/spikersoft-infrastructure#494 (merged): the token is now a documented key in our secret-store setup script and secrets docs, so it can be added and rotated properly.
  • spikerj/spikersoft-backend#1239 (open): when Gitea credentials simply aren't configured, the API logs a warning naming the missing settings, instead of filing one Staff Issue per signup. Real failures, where credentials are set but Gitea errors, are still filed. Repos are still created later when a student opens the Git Playground, so nobody is permanently left out.

What's still needed (operator step, not code): create a Gitea token for the service account that owns the student repos, store it in the secret store, restart the API, then press Retry on the existing entries. Leaving this open until that's done and the retries succeed.

Tip: when an error says something "must be configured", it usually means a missing setting rather than broken code. Quoting the exact message, as you did, saves a lot of time.

Confirmed — thanks for the clear report and for including the exact error text. It pointed straight at the cause. **What was wrong:** when a new user's profile is first created (or a child account is approved), the API tries to create that student's private Gitea repository for coding lessons. To call Gitea it needs credentials: an access token (`Gitea:AccessToken`) or a username and password. Production had the Gitea address and organization configured, but the token was blank. So every signup stopped early and filed a "needs attention" item in Staff → Issues — one per new account, exactly as you saw. The code did what it was designed to do when a setting is missing. The real gap was **configuration**, plus a bit of noise. **What's done** - spikerj/spikersoft-infrastructure#494 (merged): the token is now a documented key in our secret-store setup script and secrets docs, so it can be added and rotated properly. - spikerj/spikersoft-backend#1239 (open): when Gitea credentials simply aren't configured, the API logs a warning naming the missing settings, instead of filing one Staff Issue per signup. Real failures, where credentials are set but Gitea errors, are still filed. Repos are still created later when a student opens the Git Playground, so nobody is permanently left out. **What's still needed (operator step, not code):** create a Gitea token for the service account that owns the student repos, store it in the secret store, restart the API, then press **Retry** on the existing entries. Leaving this open until that's done and the retries succeed. Tip: when an error says something "must be configured", it usually means a missing setting rather than broken code. Quoting the exact message, as you did, saves a lot of time.
spikerj added the bug label 2026-10-02 03:42:07 +00:00
Sign in to join this conversation.