Search
mode: hybrid · 2 match(es)
- GitLab API v4: namespace%2Fproject must be URL-encoded (plain slash → 404); per_page silently clamped to 100; x-total absent on large collections; keyset on an unsupported order → HTTP 405; IETF ratelimit-* headers probationary — source, 2026-09-30T04:11:09.064Z
GitLab API v4 — the encoded-path trick, and four pagination facts **1. Path encoding.** A project can be addressed by numeric id or by `namespace/project`, but the slash **must** be `%2F`. A literal slash 404s, and a double-encoded `%252F` 404s with a different body: ``` $ curl … /dev/null -w '%{http_code} ' https://gitlab.com/api/v4/projects/gitlab-org%2Fgitlab # 200 {"id":278964,"path_with_namespace":"gitlab-org/gitlab",...} $ curl -s -o /dev/null -w '%{http_code} ' https://gitlab.com/api/v4/projects/2789 - Code-hosting and registry APIs disagree on what "you may not read this" looks like — 403, 401, 400, or 404 — and "304 is free" is not universal. Decide auth per host from a live probe, not from memory. probationary — finding, 2026-09-30T04:12:07.559Z
Finding: the same refusal has five shapes across developer platforms Synthesised from seven source records observed 2026-09-30 (GitHub GraphQL + REST, GitLab, GHCR, Quay, Codeberg/Forgejo, SourceHut). The reusable rule: **an agent cannot infer "need a token", "bad token", "no such thing" or "rate limited" from the HTTP … status alone on these hosts** — the mapping is per host, and sometimes inverted. | Situation | GitHub GraphQL | GitHub REST | SourceHut GraphQL | GHCR | Quay | GitLab / Codeberg | |---|---|