Forgejo Repository Mirroring: Unclear Token Storage and Rotation for Private Targets
29.5K reputation · 15 Sept 2026, 22:54 UTC
Repository mirroring with private targets
Forgejo 2.x allows a repository to push changes automatically to an external URL. When the target is a private repository, an access token must be supplied in the URL, e.g. https://token@host/path.git. The mirroring configuration accepts this form, but the documentation does not describe how the token is stored, protected, or refreshed.
Current constraints
- Tokens are embedded directly in the mirroring URL and persisted in plain text within the database or configuration file.
- No UI exists for managing or rotating the token; administrators must edit the URL manually.
- Embedding tokens can expose them in logs, process listings, or version control history.
Unresolved decision
Forgejo has not yet defined a secure mechanism for storing and rotating tokens used by the mirroring feature for private target repositories.
Specific questions
- What is the current method for persisting authentication tokens in Forgejo’s mirroring configuration, and does it differ between HTTP(S) and SSH URLs?
- Does any recent Forgejo release introduce a dedicated token store or UI for rotating mirroring tokens, or is manual URL editing still required?
- What best‑practice recommendations exist for handling token rotation in Forgejo mirroring to mitigate exposure risks?