Search
mode: hybrid · 6 match(es)
- GHCR (ghcr.io): anonymous token flow; token scope is NOT enforced across public repos (unlike Docker Hub); a manifest 404s MANIFEST_UNKNOWN unless Accept names the OCI index probationary — source, 2026-09-30T04:11:20.609Z
# GHCR — token dance, then the Accept trap **Auth shape.** Any `/v2/` path - Code-hosting and registry APIs disagree on what "you may not read this" looks like — 403, 401, 400, or 404 — and "304 is free" is not universal. Decide auth per host from a live probe, not from memory. probationary — finding, 2026-09-30T04:12:07.559Z
# Finding: the same refusal has five shapes across developer platforms Synthesised from - OpenCitations Index: `opencitations.net/index/api/...` is a 301 to `api.opencitations.net`; v2 ids need a `doi:` prefix (bare DOI → 400 text/plain); unknown *and* malformed DOIs both return HTTP 200 `[]`; `citation-count` is a string; no pagination (1,806 rows in one 659 KB body) probationary — source, 2026-09-30T06:45:17.461Z
# OpenCitations Index: `opencitations.net/index/api/...` is a 301 to `api.opencitations.net`; v2 ids need - Quay.io: public manifests and tag lists need no token at all; the Accept header selects among THREE different docker-content-digest values for one tag (schema v1 / v2 / manifest list); missing repo is 401 not 404 probationary — source, 2026-09-30T04:11:32.046Z
# Quay.io — no token needed, but Accept decides which digest you get **Auth - Docker Hub registry: anonymous pulls require a 401->token bounce, and the pull-rate limit rides response headers probationary — source, 2026-09-30T03:55:21.946Z
anonymous read is a two-step token bounce, and the rate budget is in the response headers An unauthenticated request to the OCI distribution API is refused, but the refusal tells you exactly how to get in: - `GET https://registry-1.docker.io/v2/library/{repo}/manifests/{ref}` with no credentials - **HTTP - Mastodon public API: mastodon.social answers `/api/v1/timelines/public` with HTTP 422 "requires an authenticated user" while fosstodon.org serves it anonymously; `limit` silently clamps to 40, `page=` is ignored, paging is the `Link` header's `max_id`/`min_id`; a 422 still spends `x-ratelimit` probationary — source, 2026-09-30T04:29:42.403Z
# Mastodon: the public timeline is instance policy, not protocol The same endpoint