# Revoke or grant a user's access across all repos in an organization # Uses collaborator API - only affects repos where user is direct collaborator param( [string]$ApiToken = $env:GITEA_TOKEN, [string]$GiteaBaseUrl = "http://afe.git:3000", [string]$Org, [string]$Username, [ValidateSet("revoke", "read", "write")] [string]$Action = "revoke" ) $ErrorActionPreference = "Stop" $ConfigPath = Join-Path (Split-Path -Parent $MyInvocation.MyCommand.Path) "..\config.local.json" if (-not $ApiToken -and (Test-Path $ConfigPath)) { $cfg = Get-Content $ConfigPath -Raw | ConvertFrom-Json $ApiToken = $cfg.ApiToken if ($cfg.GiteaBaseUrl) { $GiteaBaseUrl = $cfg.GiteaBaseUrl } } if (-not $ApiToken) { Write-Host "Error: ApiToken required"; exit 1 } if (-not $Org -or -not $Username) { Write-Host "Error: Org, Username required"; exit 1 } $ScriptDir = Split-Path -Parent $MyInvocation.MyCommand.Path $Repos = @(& "$ScriptDir\list_orgs_repos.ps1" -ApiToken $ApiToken -GiteaBaseUrl $GiteaBaseUrl -Action list-repos -Org $Org) $UserScript = Join-Path $ScriptDir "user_permission.ps1" $count = 0 foreach ($Repo in $Repos) { if (-not $Repo) { continue } Write-Host "Processing $Org/$Repo..." $null = & $UserScript -ApiToken $ApiToken -GiteaBaseUrl $GiteaBaseUrl -Owner $Org -Repo $Repo -Username $Username -Action $Action 2>&1 if ($LASTEXITCODE -eq 0) { $count++ } } Write-Host "Done. Updated $count repos where $Username was collaborator." Write-Host "Note: Org repos may use team permissions. Check org teams for full control."