bc7f506311
Investigates whether the Gitea `tea` CLI can be authenticated via a header-injecting proxy so the token never enters the container — even as an env var. Parallels the OAuth-token research note. Recommends an in-container root-owned reverse proxy as the lowest-friction shape, and flags the unavoidable tradeoff that the agent retains the token's full API scope (no exfil ≠ no harm). Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>