Validations
Feeds Verdaccio and BaGet Auth Validation
Command:
Superseded (2026-07-01): the npm/NuGet feeds validated here (Verdaccio/BaGet) were retired and replaced by the Gitea package registry (
gitea.perspective-v.com/api/packages/perspective-v/...). Kept as a historical record.
- Date: 2026-04-16
- Scope: VPS runtime auth behavior for
npm.perspective-v.com(Verdaccio) andnuget.perspective-v.com(BaGet).
Live Verdaccio Policy Check
Command:
docker exec verdaccio sh -lc "grep -n 'max_users\|access: \$all\|publish: \$authenticated\|unpublish: \$authenticated' /verdaccio/conf/config.yaml"Result:
6: max_users: -1
14: access: $all
15: publish: $authenticated
16: unpublish: $authenticated
19: access: $all
20: publish: $authenticated
21: unpublish: $authenticatedVerdaccio Endpoint Validation
- Unknown-user self-registration is rejected.
Command:
curl -sS -D /tmp/verd-adduser2-headers.txt -o /tmp/verd-adduser2-body.json -H "content-type: application/json" -X PUT --data '{"name":"probe-user2","password":"StrongPass123!","email":"probe@example.com"}' https://npm.perspective-v.com/-/user/org.couchdb.user:probe-user2Result:
HTTP/2 409
{"error":"user registration disabled"}- Anonymous package read works.
Command:
curl -sS -o /dev/null -w "%{http_code}\n" https://npm.perspective-v.com/lodashResult:
200- Unauthenticated write is blocked.
Command:
curl -sS -o /dev/null -w "%{http_code}\n" -X PUT https://npm.perspective-v.com/pv-ci-probe-20260416Result:
401- Prior authenticated publish artifact remains accessible.
Command:
curl -sS -o /dev/null -w "%{http_code}\n" https://npm.perspective-v.com/pv-ci-probe-20260416Result:
200- Temporary probe publisher cleanup confirmed (
adminonly in htpasswd snapshot).
Result:
admin:Nf3gqDiEDTHkI:autocreated 2026-04-09T22:44:20.450ZBaGet Endpoint Validation
NuGet v3 index read endpoint:
curl -sS -o /dev/null -w "%{http_code}\n" https://nuget.perspective-v.com/v3/index.jsonResult:
200NuGet push endpoint with correct binary content type:
- No API key:
curl -sS -o /dev/null -w "%{http_code}\n" -X PUT -H "Content-Type: application/octet-stream" --data-binary @/tmp/baget-probe.nupkg https://nuget.perspective-v.com/api/v2/packageResult:
401- With API key:
set +H && K=$(grep '^BAGET_API_KEY=' runtime/environments/vps/infrastructure/feeds/.env | cut -d= -f2-) && curl -sS -o /dev/null -w "%{http_code}\n" -X PUT -H "Content-Type: application/octet-stream" -H "X-NuGet-ApiKey: ${K}" --data-binary @/tmp/baget-probe.nupkg https://nuget.perspective-v.com/api/v2/packageResult:
409Interpretation: authenticated request reached publish conflict path (duplicate package), while unauthenticated request was rejected.
Notes
- Initial BaGet probe errors (
500) were caused by malformed upload semantics; sending raw package bytes withContent-Type: application/octet-streamresolved endpoint parsing and produced expected auth outcomes (401/409).