Affected by GO-2025-4258
and 2 other vulnerabilities
GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
InstallDone shows the "post-install" page, makes it easier to develop the page.
The name is not called as "PostInstall" to avoid misinterpretation as a handler for "POST /install"