# Organization Secrets not authorized when dot in org name

**URL:** <https://drone.discourse.group/t/organization-secrets-not-authorized-when-dot-in-org-name/12046>\
**Category:** Drone Bugs\
**Created:** [May 20, 2022, 9:25pm UTC](https://drone.discourse.group/t/organization-secrets-not-authorized-when-dot-in-org-name/12046 "2022-05-20T21:25:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mthie](https://avatars.discourse-cdn.com/v4/letter/m/f07891/32.png) [@mthie](https://drone.discourse.group/u/mthie)\
**Post date:** [May 20, 2022, 9:25pm UTC](https://drone.discourse.group/t/organization-secrets-not-authorized-when-dot-in-org-name/12046/1 "2022-05-20T21:25:00Z")

</div>

As soon as an organization has a dot (.) in the name, the API always returns an HTTP Error 401, the content is `{"message":"Forbidden"}`.

---

<div class="post-metadata">

**Author:** ![Femumme](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/femumme/32/7629_2.png) [@Femumme](https://drone.discourse.group/u/Femumme)\
**Post date:** [May 20, 2022, 9:48pm UTC](https://drone.discourse.group/t/organization-secrets-not-authorized-when-dot-in-org-name/12046/2 "2022-05-20T21:48:32Z")

</div>

I notice a similar issue, I’ve got the latest drone version running (2.12.0) with a gitea server (v1.14.0).

I can’t access any organization secrets at all, the name of the organization doesn’t matter. Additionally, the UI seems to have an issue in the errorhandling of the api call, cause it throws a render error and doesn’t display anything at all.

To validate that this issue seems to relate with gitea, I created another identical deployment with github and it works flawless with github.

---

<div class="post-metadata">

**Author:** ![mthie](https://avatars.discourse-cdn.com/v4/letter/m/f07891/32.png) [@mthie](https://drone.discourse.group/u/mthie)\
**Post date:** [May 20, 2022, 10:01pm UTC](https://drone.discourse.group/t/organization-secrets-not-authorized-when-dot-in-org-name/12046/3 "2022-05-20T22:01:44Z")

</div>

thb it works perfectly with only letters in the organization name. But yes, the render error is annoying.

---

<div class="post-metadata">

**Author:** ![Femumme](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/femumme/32/7629_2.png) [@Femumme](https://drone.discourse.group/u/Femumme)\
**Post date:** [May 21, 2022, 7:25pm UTC](https://drone.discourse.group/t/organization-secrets-not-authorized-when-dot-in-org-name/12046/4 "2022-05-21T19:25:23Z")

</div>

Yeah, I only tested names without special characters. I hope this gets fixed soon, cause the organization secret feature as well as the template feature (which doesn’t work with the same error code) would be really useful for me.
