{"thread":{"id":"26356","subject":"Permissions and authorisations in git repository","startedAt":"2011-01-28T11:41:24Z","lastAt":"2011-01-29T17:28:15Z","messageCount":3,"participants":["vikram2rhyme","Konstantin Khomoutov","Enrico Weigelt"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"159978","messageId":"1296214884133-5969556.post@n2.nabble.com","threadId":"26356","inReplyTo":null,"subject":"Permissions and authorisations in git repository","fromName":"vikram2rhyme","fromEmail":"vikram2rhyme@gmail.com","sentAt":"2011-01-28T11:41:24Z","receivedAt":"2011-01-28T11:41:24Z","isPatch":false,"sender":{"key":"vikram2rhyme@gmail.com","avatar":null},"body":"\nHello friends\nI am wondering if there are any permission and authorization control over\ngit \nrepository. I have gone through git manual but there is no discussion on it.\nOn the internet i searched but hardy i found anything. Please help me if\nthere\nis any permission control in distributed environment in git repository\n-- \nView this message in context: http://git.661346.n2.nabble.com/Permissions-and-authorisations-in-git-repository-tp5969556p5969556.html\nSent from the git mailing list archive at Nabble.com.\n"},{"id":"159980","messageId":"20110128150631.33be0a9d.kostix@domain007.com","threadId":"26356","inReplyTo":"1296214884133-5969556.post@n2.nabble.com","subject":"Re: Permissions and authorisations in git repository","fromName":"Konstantin Khomoutov","fromEmail":"flatworm@users.sourceforge.net","sentAt":"2011-01-28T12:06:31Z","receivedAt":"2011-01-28T12:06:31Z","isPatch":false,"sender":{"key":"flatworm@users.sourceforge.net","avatar":null},"body":"On Fri, 28 Jan 2011 03:41:24 -0800 (PST)\nvikram2rhyme <vikram2rhyme@gmail.com> wrote:\n\n> I am wondering if there are any permission and authorization control\n> over git repository.\n[...]\n\nIn the simplest case -- r/w access via SSH -- those who know the\nlogin/password or possess the necessary private key have (full) access\nto the repository. The repository can also be made accessible for\nread-only via Git protocol (as a whole as well). This can be used for\nsimple write/read access discrimination.\nIf a more fine-grained control\nis needed, third-party tools exist: gitolite:\nhttps://github.com/sitaramc/gitolite gitosis: http://swik.net/gitosis\n\nNote that as Git does not suffer from a centralised VCS syndrome of\nhaving a single repository shared by everyone involved, the problem\nyou're facing might not exist at all: every developer or a group of\nrelated developers maintains their own repository and a \"central\"\nrepository (in whatever sense you're willing to put into it) is owned\nby a special person or a group of persons.\n"},{"id":"160030","messageId":"20110129172815.GB602@nibiru.local","threadId":"26356","inReplyTo":"20110128150631.33be0a9d.kostix@domain007.com","subject":"Re: Permissions and authorisations in git repository","fromName":"Enrico Weigelt","fromEmail":"weigelt@metux.de","sentAt":"2011-01-29T17:28:15Z","receivedAt":"2011-01-29T17:28:15Z","isPatch":false,"sender":{"key":"weigelt@metux.de","avatar":null},"body":"* Konstantin Khomoutov <flatworm@users.sourceforge.net> wrote:\n\n<snip>\n\nIn fact, git does not have any access control whatsoever. It relies\non what the underlying transport protocol allows it to do.\n\nWith ssh, you could wrap the commands into some script which checks,\nthe permissions on calling-in user or key (eg. restrict write access\non certain refs to certain people). You could do even more fancy\nthings like given everybody (or certain people) unrestricted write\naccess, but under the hood put their rename the updated refs\n(eg. you can push 'master', but on the server, refs/heads/master\nwont be overwritten, instead it goes to refs/heads/konstantin/master).\n\nSome people (coming from strictly-central ideologies) might consider\ngit's access control angonsticity a drawback, but IMHO it's a very\ngood thing - git doesn't want to be a full-blown \"out-of-the-box\"\nVCS (like, eg. clearcase), but more a lightweight toolkit to easily\nbuild your own.\n\n\ncu\n-- \n----------------------------------------------------------------------\n Enrico Weigelt, metux IT service -- http://www.metux.de/\n\n phone:  +49 36207 519931  email: weigelt@metux.de\n mobile: +49 151 27565287  icq:   210169427         skype: nekrad666\n----------------------------------------------------------------------\n Embedded-Linux / Portierung / Opensource-QM / Verteilte Systeme\n----------------------------------------------------------------------\n"}]}