{"thread":{"id":"22967","subject":"git-http-backend and Authenticated Pushes","startedAt":"2010-03-09T17:08:48Z","lastAt":"2010-03-10T02:13:46Z","messageCount":6,"participants":["Ryan Phillips","Antonio García Domínguez","BJ Hargrave","Shawn O. Pearce"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"136456","messageId":"46a47f951003090908s62512bd7xcbb707205958e004@mail.gmail.com","threadId":"22967","inReplyTo":null,"subject":"git-http-backend and Authenticated Pushes","fromName":"Ryan Phillips","fromEmail":"ryan@trolocsis.com","sentAt":"2010-03-09T17:08:48Z","receivedAt":"2010-03-09T17:08:48Z","isPatch":false,"sender":{"key":"ryan@trolocsis.com","avatar":"https://gravatar.com/avatar/777ca9328f234f1c6e156794d6322bbfd425be6bc402c8fe62d9d11e1a32ba2b?d=mp&s=160"},"body":"Hi All,\n\nI'm trying to follow the git-http-backend man page on setting up\nauthenticated pushes to my apache server. Pulls work fine, and fully\nauthenticated pushes work fine. However, when I try and setup\nanonymous pulls and authenticated pushes the push fails.\n\nI believe the culprit is this 403 error:\n\n192.168.1.1 - - [09/Mar/2010:09:01:43 -0800] \"GET\n/git/test.git/info/refs?service=git-receive-pack HTTP/1.1\" 403 - \"-\"\n\"git/1.7.0.2.dirty\"\n\nAnybody know what I missed?\n\nRegards,\nRyan\n\nMy vhost replaced with example.com:\n\n<VirtualHost *:80>\n        SetEnv GIT_PROJECT_ROOT /home/httpd/domains/example.com/repo\n        SetEnv GIT_HTTP_EXPORT_ALL\n        SetEnv GITWEB_CONFIG /home/httpd/domains/example.com/gitweb.conf\n\n        RewriteEngine on\n        RewriteRule ^/$     /git/ [PT]\n\n        <Directory /usr/local/git>\n           Options Indexes FollowSymLinks MultiViews Includes ExecCGI\n           AllowOverride None\n           Order allow,deny\n           Allow from all\n        </Directory>\n\n        <LocationMatch \"^/git/.*/git-receive-pack$\">\n            AuthType Basic\n            AuthName \"Git Access\"\n            AuthUserFile /home/httpd/domains/example.com/.htpasswd\n            Require valid-user\n        </LocationMatch>\n        ScriptAliasMatch \\\n                \"(?x)^/git/(.*/(HEAD | \\\n                                info/refs | \\\n                                objects/(info/[^/]+ | \\\n                                         [0-9a-f]{2}/[0-9a-f]{38} | \\\n                                         pack/pack-[0-9a-f]{40}\\.(pack|idx)) | \\\n                                git-(upload|receive)-pack))$\" \\\n                /usr/local/git/current/libexec/git-core/git-http-backend/$1\n\n        ScriptAlias /git/ /usr/local/git/current/gitweb/gitweb.cgi/\n\n        Alias       /gitweb.css       /usr/local/git/current/gitweb/gitweb.css\n        Alias       /git-logo.png     /usr/local/git/current/gitweb/git-logo.png\n        Alias       /git-favicon.png\n/usr/local/git/current/gitweb/git-favicon.png\n\n        ServerName example.com\n        ServerAlias *.example.com\n        ErrorLog /home/httpd/domains/example.com/logs/error_log\n        CustomLog /home/httpd/domains/example.com/logs/access_log combined\n</VirtualHost>\n"},{"id":"136463","messageId":"2b8265361003091101x1e3a3410hc3be2446dc7ddce@mail.gmail.com","threadId":"22967","inReplyTo":"46a47f951003090908s62512bd7xcbb707205958e004@mail.gmail.com","subject":"Re: git-http-backend and Authenticated Pushes","fromName":"Antonio García Domínguez","fromEmail":"nyoescape@gmail.com","sentAt":"2010-03-09T19:01:12Z","receivedAt":"2010-03-09T19:01:12Z","isPatch":false,"sender":{"key":"nyoescape@gmail.com","avatar":null},"body":"Hi Ryan,\n\n> Anybody know what I missed?\n\nI think you need authentication for everything regarding\ngit-receive-pack, even that GET request. I ran into that issue while\npatching Redmine's mod-perl authentication module to handle smart HTTP\n[1]. Public projects (which have anonymous pull and authenticated\npush) would just not work.\n\nGit first GETs that URL you mention, and then POSTs to the usual\ngit-receive-pack URL. Both need authentication, but you're only\nauthenticating the POST. I suggest you authenticate every request to\nthe git-receive-pack service. Try something like this (warning,\nuntested!):\n\n>        <LocationMatch \"^/git/.*/[^/]*git-receive-pack$\">\n\nIf anyone else has a better idea, I'd like to know myself :-).\n\n[1]: http://www.redmine.org/issues/4905\n\nCheers,\nAntonio\n"},{"id":"136464","messageId":"64E1366D-31FC-4E0D-9F7D-35E6387E2EC1@bjhargrave.com","threadId":"22967","inReplyTo":"2b8265361003091101x1e3a3410hc3be2446dc7ddce@mail.gmail.com","subject":"Re: git-http-backend and Authenticated Pushes","fromName":"BJ Hargrave","fromEmail":"bj@bjhargrave.com","sentAt":"2010-03-09T19:17:43Z","receivedAt":"2010-03-09T19:17:43Z","isPatch":false,"sender":{"key":"bj@bjhargrave.com","avatar":"https://gravatar.com/avatar/48e60c01177c0e8d3e60c996d54fbe36cf70058efcdd020375b4055e34fc05d7?d=mp&s=160"},"body":"On Mar 9, 2010, at 14:01 , Antonio García Domínguez wrote:\n\n> Git first GETs that URL you mention, and then POSTs to the usual\n> git-receive-pack URL. Both need authentication, but you're only\n> authenticating the POST. I suggest you authenticate every request to\n> the git-receive-pack service. Try something like this (warning,\n> untested!):\n> \n>>       <LocationMatch \"^/git/.*/[^/]*git-receive-pack$\"\n\nLocationMatch will not match against the query string which is where the service name is. To match against the query string, you would need to do something like:\n\n\tRewriteCond %{QUERY_STRING} service=git-receive-pack\n\tRewriteRule .* - [E=AUTHREQUIRED:yes]\nthen\n\tOrder Allow,Deny\n\tDeny from env=AUTHREQUIRED\n\tAllow from all\n\tSatisfy Any\n\t# Add other auth statements for password file.\n\n(also untested :-)\n\nBut, I would think using <LimitExcept GET PROPFIND OPTIONS REPORT> to protect against \"writing\" to the repo without auth should be sufficient.\n-- \n\nBJ Hargrave\n"},{"id":"136465","messageId":"2b8265361003091123g780a9b36g5ec641d465c7df02@mail.gmail.com","threadId":"22967","inReplyTo":"64E1366D-31FC-4E0D-9F7D-35E6387E2EC1@bjhargrave.com","subject":"Re: git-http-backend and Authenticated Pushes","fromName":"Antonio García Domínguez","fromEmail":"nyoescape@gmail.com","sentAt":"2010-03-09T19:23:48Z","receivedAt":"2010-03-09T19:23:48Z","isPatch":false,"sender":{"key":"nyoescape@gmail.com","avatar":null},"body":"Hi BJ,\n\n> LocationMatch will not match against the query string which is where the service name is. To match against the query string, you would need to do something like:\n\nOops, you're right. I'm actually matching the unparsed URL using a\nregexp in a Perl authentication module, so I missed that Apache\ndetail. Your snippet looks good to me.\n\n> But, I would think using <LimitExcept GET PROPFIND OPTIONS REPORT> to protect against \"writing\" to the repo without auth should be sufficient.\n\nBut that doesn't work for the smart HTTP method. Limiting by method is\nOK for dumb HTTP (as we're basically just modifying files using\nWebDAV), but the git-http-backend CGI only uses GET and POST, and\nrequires authentication depending not on the HTTP method, but what\nservice is being used.\n\nOr so I think :-).\n\nCheers,\nAntonio\n"},{"id":"136466","messageId":"20100309192726.GA12461@spearce.org","threadId":"22967","inReplyTo":"46a47f951003090908s62512bd7xcbb707205958e004@mail.gmail.com","subject":"Re: git-http-backend and Authenticated Pushes","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2010-03-09T19:27:26Z","receivedAt":"2010-03-09T19:27:26Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Ryan Phillips <ryan@trolocsis.com> wrote:\n> I'm trying to follow the git-http-backend man page on setting up\n> authenticated pushes to my apache server. Pulls work fine, and fully\n> authenticated pushes work fine. However, when I try and setup\n> anonymous pulls and authenticated pushes the push fails.\n> \n> I believe the culprit is this 403 error:\n> \n> 192.168.1.1 - - [09/Mar/2010:09:01:43 -0800] \"GET\n> /git/test.git/info/refs?service=git-receive-pack HTTP/1.1\" 403 - \"-\"\n> \"git/1.7.0.2.dirty\"\n\nUgh.  Looks like I didn't design this thing right.\n\nThe backend wants you to be authenticated before it will service\nthe git-receive-pack advertisement.  Even though its the same\ndata as the git-upload-pack advertisement (but slightly different\ncapability strings).\n\nMaybe we should consider doing something like this patch so that\nthe advertisement under info/refs?service=git-receive-pack can be\nsent without needing authentication.  My only hesitation is this\nmakes it harder for the client to setup the authentication before\nit needs to transmit the pack file, which may mean it needs to send\nthe pack twice.\n\n\ndiff --git a/http-backend.c b/http-backend.c\nindex 345c12b..462b07c 100644\n--- a/http-backend.c\n+++ b/http-backend.c\n@@ -312,11 +312,6 @@ static struct rpc_service *select_service(const char *name)\n \n \tif (!svc)\n \t\tforbidden(\"Unsupported service: '%s'\", name);\n-\n-\tif (svc->enabled < 0) {\n-\t\tconst char *user = getenv(\"REMOTE_USER\");\n-\t\tsvc->enabled = (user && *user) ? 1 : 0;\n-\t}\n \tif (!svc->enabled)\n \t\tforbidden(\"Service not enabled: '%s'\", svc->name);\n \treturn svc;\n@@ -519,6 +514,12 @@ static void service_rpc(char *service_name)\n \tstruct rpc_service *svc = select_service(service_name);\n \tstruct strbuf buf = STRBUF_INIT;\n \n+\tif (svc->enabled < 0) {\n+\t\tconst char *user = getenv(\"REMOTE_USER\");\n+\t\tif (!user || !*user)\n+\t\t\tforbidden(\"Service not enabled: '%s'\", svc->name);\n+\t}\n+\n \tstrbuf_reset(&buf);\n \tstrbuf_addf(&buf, \"application/x-git-%s-request\", svc->name);\n \tcheck_content_type(buf.buf);\n \n-- \nShawn.\n"},{"id":"136499","messageId":"46a47f951003091813p768fdb58v454f2553a8b6ed8@mail.gmail.com","threadId":"22967","inReplyTo":"20100309192726.GA12461@spearce.org","subject":"Re: git-http-backend and Authenticated Pushes","fromName":"Ryan Phillips","fromEmail":"ryan@trolocsis.com","sentAt":"2010-03-10T02:13:46Z","receivedAt":"2010-03-10T02:13:46Z","isPatch":false,"sender":{"key":"ryan@trolocsis.com","avatar":"https://gravatar.com/avatar/777ca9328f234f1c6e156794d6322bbfd425be6bc402c8fe62d9d11e1a32ba2b?d=mp&s=160"},"body":"On Tue, Mar 9, 2010 at 1:27 PM, Shawn O. Pearce <spearce@spearce.org> wrote:\n> Ryan Phillips <ryan@trolocsis.com> wrote:\n>> I'm trying to follow the git-http-backend man page on setting up\n>> authenticated pushes to my apache server. Pulls work fine, and fully\n>> authenticated pushes work fine. However, when I try and setup\n>> anonymous pulls and authenticated pushes the push fails.\n>>\n>> I believe the culprit is this 403 error:\n>>\n>> 192.168.1.1 - - [09/Mar/2010:09:01:43 -0800] \"GET\n>> /git/test.git/info/refs?service=git-receive-pack HTTP/1.1\" 403 - \"-\"\n>> \"git/1.7.0.2.dirty\"\n>\n> Ugh.  Looks like I didn't design this thing right.\n>\n> The backend wants you to be authenticated before it will service\n> the git-receive-pack advertisement.  Even though its the same\n> data as the git-upload-pack advertisement (but slightly different\n> capability strings).\n>\n> Maybe we should consider doing something like this patch so that\n> the advertisement under info/refs?service=git-receive-pack can be\n> sent without needing authentication.  My only hesitation is this\n> makes it harder for the client to setup the authentication before\n> it needs to transmit the pack file, which may mean it needs to send\n> the pack twice.\n>\n\nThank you everyone for your response.\n\nShawn: That patch does fix the issue for now.\n\nRegards,\nRyan\n"}]}