Drop the GITEA_TOKEN gate and pass no explicit token: gitea-release-action defaults to the run's automatic github.token, so the release page needs only contents: write. Keep the npm publish gated on NPM_TOKEN, but add a final always() step that fails the job unless both the release page and npm publish reported success, so a skipped npm half is an explicit red job instead of a silently green one.