Perspective V Docs
Validations

Feeds Verdaccio and BaGet Auth Validation

Command:

Superseded (2026-07-01): the npm/NuGet feeds validated here (Verdaccio/BaGet) were retired and replaced by the Gitea package registry (gitea.perspective-v.com/api/packages/perspective-v/...). Kept as a historical record.

  • Date: 2026-04-16
  • Scope: VPS runtime auth behavior for npm.perspective-v.com (Verdaccio) and nuget.perspective-v.com (BaGet).

Live Verdaccio Policy Check

Command:

docker exec verdaccio sh -lc "grep -n 'max_users\|access: \$all\|publish: \$authenticated\|unpublish: \$authenticated' /verdaccio/conf/config.yaml"

Result:

6:    max_users: -1
14:    access: $all
15:    publish: $authenticated
16:    unpublish: $authenticated
19:    access: $all
20:    publish: $authenticated
21:    unpublish: $authenticated

Verdaccio Endpoint Validation

  1. Unknown-user self-registration is rejected.

Command:

curl -sS -D /tmp/verd-adduser2-headers.txt -o /tmp/verd-adduser2-body.json -H "content-type: application/json" -X PUT --data '{"name":"probe-user2","password":"StrongPass123!","email":"probe@example.com"}' https://npm.perspective-v.com/-/user/org.couchdb.user:probe-user2

Result:

HTTP/2 409
{"error":"user registration disabled"}
  1. Anonymous package read works.

Command:

curl -sS -o /dev/null -w "%{http_code}\n" https://npm.perspective-v.com/lodash

Result:

200
  1. Unauthenticated write is blocked.

Command:

curl -sS -o /dev/null -w "%{http_code}\n" -X PUT https://npm.perspective-v.com/pv-ci-probe-20260416

Result:

401
  1. Prior authenticated publish artifact remains accessible.

Command:

curl -sS -o /dev/null -w "%{http_code}\n" https://npm.perspective-v.com/pv-ci-probe-20260416

Result:

200
  1. Temporary probe publisher cleanup confirmed (admin only in htpasswd snapshot).

Result:

admin:Nf3gqDiEDTHkI:autocreated 2026-04-09T22:44:20.450Z

BaGet Endpoint Validation

NuGet v3 index read endpoint:

curl -sS -o /dev/null -w "%{http_code}\n" https://nuget.perspective-v.com/v3/index.json

Result:

200

NuGet push endpoint with correct binary content type:

  1. No API key:
curl -sS -o /dev/null -w "%{http_code}\n" -X PUT -H "Content-Type: application/octet-stream" --data-binary @/tmp/baget-probe.nupkg https://nuget.perspective-v.com/api/v2/package

Result:

401
  1. With API key:
set +H && K=$(grep '^BAGET_API_KEY=' runtime/environments/vps/infrastructure/feeds/.env | cut -d= -f2-) && curl -sS -o /dev/null -w "%{http_code}\n" -X PUT -H "Content-Type: application/octet-stream" -H "X-NuGet-ApiKey: ${K}" --data-binary @/tmp/baget-probe.nupkg https://nuget.perspective-v.com/api/v2/package

Result:

409

Interpretation: authenticated request reached publish conflict path (duplicate package), while unauthenticated request was rejected.

Notes

  • Initial BaGet probe errors (500) were caused by malformed upload semantics; sending raw package bytes with Content-Type: application/octet-stream resolved endpoint parsing and produced expected auth outcomes (401/409).

On this page