{"thread":{"id":"27852","subject":"Restricted git push ?","startedAt":"2011-07-19T09:36:37Z","lastAt":"2011-07-19T16:06:24Z","messageCount":7,"participants":["J. Bakshi","Sitaram Chamarty"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"171647","messageId":"20110719150637.596b9791@shiva.selfip.org","threadId":"27852","inReplyTo":null,"subject":"Restricted git push ?","fromName":"J. Bakshi","fromEmail":"joydeep@infoservices.in","sentAt":"2011-07-19T09:36:37Z","receivedAt":"2011-07-19T09:36:37Z","isPatch":false,"sender":{"key":"joydeep@infoservices.in","avatar":null},"body":"Hello list,\n\nI have installed git repo based on http://  protocol and both read+write access is based on a htpasswd based authentication. The git repo is \"bare\" so that push is possible. But I like to have push from a limited users only, not from all. For the rest, only pull should be possible. Is there any way to achieve this type of ACL ?\n\nThanks\n"},{"id":"171648","messageId":"CAMK1S_jsv-pFy6bNPG=EK=4YsJOh3GUZ+_DAq6n36ajWuhyNaQ@mail.gmail.com","threadId":"27852","inReplyTo":"20110719150637.596b9791@shiva.selfip.org","subject":"Re: Restricted git push ?","fromName":"Sitaram Chamarty","fromEmail":"sitaramc@gmail.com","sentAt":"2011-07-19T10:05:42Z","receivedAt":"2011-07-19T10:05:42Z","isPatch":false,"sender":{"key":"sitaramc@gmail.com","avatar":"https://avatars.githubusercontent.com/u/43316?v=4"},"body":"On Tue, Jul 19, 2011 at 3:06 PM, J. Bakshi <joydeep@infoservices.in> wrote:\n> Hello list,\n>\n> I have installed git repo based on http://  protocol and both read+write access is based on a htpasswd based authentication. The git repo is \"bare\" so that push is possible. But I like to have push from a limited users only, not from all. For the rest, only pull should be possible. Is there any way to achieve this type of ACL ?\n\nman git-http-backend has an example config described thus:  \"To enable\nanonymous read access but authenticated write access...\".  It\ncertainly sounds like what you want.\n\nNot sure what sort of http access you have setup but ideally you\nshould have used that one to setup your server.  If you did, changing\nit to work this way should be easy now.\n"},{"id":"171650","messageId":"20110719160311.10f2364d@shiva.selfip.org","threadId":"27852","inReplyTo":"CAMK1S_jsv-pFy6bNPG=EK=4YsJOh3GUZ+_DAq6n36ajWuhyNaQ@mail.gmail.com","subject":"Re: Restricted git push ?","fromName":"J. Bakshi","fromEmail":"joydeep@infoservices.in","sentAt":"2011-07-19T10:33:11Z","receivedAt":"2011-07-19T10:33:11Z","isPatch":false,"sender":{"key":"joydeep@infoservices.in","avatar":null},"body":"On Tue, 19 Jul 2011 15:35:42 +0530\nSitaram Chamarty <sitaramc@gmail.com> wrote:\n\n> On Tue, Jul 19, 2011 at 3:06 PM, J. Bakshi <joydeep@infoservices.in> wrote:\n> > Hello list,\n> >\n> > I have installed git repo based on http://  protocol and both read+write access is based on a htpasswd based authentication. The git repo is \"bare\" so that push is possible. But I like to have push from a limited users only, not from all. For the rest, only pull should be possible. Is there any way to achieve this type of ACL ?\n> \n> man git-http-backend has an example config described thus:  \"To enable\n> anonymous read access but authenticated write access...\".  It\n> certainly sounds like what you want.\n> \n> Not sure what sort of http access you have setup \n\nI have \n\n``````````\n<Location /git>\nAuthType Basic\n# Message to give to the committer\nAuthName \"Write access requires a password\"\n# File listing users with write (commit) access\nAuthUserFile /home/svn/PASSWD\nRequire valid-user\n</Location>\n``````````\n\nSo authentication is require forman git-http-backend both read and write. Now to use one more level to restrict push user I have added one more restriction like\n\n<LocationMatch \"^/git/.*/git-receive-pack$\">\nAuthType Basic\n# Message to give to the committer\nAuthName \"Write access requires a password\"\n# File listing users with write (commit) access\nAuthUserFile /home/git/pushACL\nRequire valid-user\n</LocationMatch>\n\nread access is working fine, but write access not. log reports \n\n````````\n user testuser not found: /git/web.git/info/refs\n``````````\n\nDon't know why it is searching at /git/web.git/info/refs !!\n"},{"id":"171651","messageId":"20110719161529.47268b52@shiva.selfip.org","threadId":"27852","inReplyTo":"20110719160311.10f2364d@shiva.selfip.org","subject":"Re: Restricted git push ?","fromName":"J. Bakshi","fromEmail":"joydeep@infoservices.in","sentAt":"2011-07-19T10:45:29Z","receivedAt":"2011-07-19T10:45:29Z","isPatch":false,"sender":{"key":"joydeep@infoservices.in","avatar":null},"body":"On Tue, 19 Jul 2011 16:03:11 +0530\n\"J. Bakshi\" <joydeep@infoservices.in> wrote:\n\n> On Tue, 19 Jul 2011 15:35:42 +0530\n> Sitaram Chamarty <sitaramc@gmail.com> wrote:\n> \n> > On Tue, Jul 19, 2011 at 3:06 PM, J. Bakshi <joydeep@infoservices.in> wrote:\n> > > Hello list,\n> > >\n> > > I have installed git repo based on http://  protocol and both read+write access is based on a htpasswd based authentication. The git repo is \"bare\" so that push is possible. But I like to have push from a limited users only, not from all. For the rest, only pull should be possible. Is there any way to achieve this type of ACL ?\n> > \n> > man git-http-backend has an example config described thus:  \"To enable\n> > anonymous read access but authenticated write access...\".  It\n> > certainly sounds like what you want.\n> > \n> > Not sure what sort of http access you have setup \n> \n> I have \n> \n> ``````````\n> <Location /git>\n> AuthType Basic\n> # Message to give to the committer\n> AuthName \"Write access requires a password\"\n> # File listing users with write (commit) access\n> AuthUserFile /home/svn/PASSWD\n> Require valid-user\n> </Location>\n> ``````````\n> \n> So authentication is require forman git-http-backend both read and write. Now to use one more level to restrict push user I have added one more restriction like\n> \n> <LocationMatch \"^/git/.*/git-receive-pack$\">\n> AuthType Basic\n> # Message to give to the committer\n> AuthName \"Write access requires a password\"\n> # File listing users with write (commit) access\n> AuthUserFile /home/git/pushACL\n> Require valid-user\n> </LocationMatch>\n> \n> read access is working fine, but write access not. log reports \n> \n> ````````\n>  user testuser not found: /git/web.git/info/refs\n> ``````````\n> \n> Don't know why it is searching at /git/web.git/info/refs !!\n> \n\nOK, seems the write authentication is checked twice. one for the first stanza for read access and second-time for the 2nd stanza the write access.\nHow can I tweak the first stanza only for read access ?\n"},{"id":"171652","messageId":"20110719164037.05fd4a36@shiva.selfip.org","threadId":"27852","inReplyTo":"20110719161529.47268b52@shiva.selfip.org","subject":"Re: Restricted git push ?","fromName":"J. Bakshi","fromEmail":"joydeep@infoservices.in","sentAt":"2011-07-19T11:10:37Z","receivedAt":"2011-07-19T11:10:37Z","isPatch":false,"sender":{"key":"joydeep@infoservices.in","avatar":null},"body":"On Tue, 19 Jul 2011 16:15:29 +0530\n\"J. Bakshi\" <joydeep@infoservices.in> wrote:\n\n> On Tue, 19 Jul 2011 16:03:11 +0530\n> \"J. Bakshi\" <joydeep@infoservices.in> wrote:\n> \n> > On Tue, 19 Jul 2011 15:35:42 +0530\n> > Sitaram Chamarty <sitaramc@gmail.com> wrote:\n> > \n> > > On Tue, Jul 19, 2011 at 3:06 PM, J. Bakshi <joydeep@infoservices.in> wrote:\n> > > > Hello list,\n> > > >\n> > > > I have installed git repo based on http://  protocol and both read+write access is based on a htpasswd based authentication. The git repo is \"bare\" so that push is possible. But I like to have push from a limited users only, not from all. For the rest, only pull should be possible. Is there any way to achieve this type of ACL ?\n> > > \n> > > man git-http-backend has an example config described thus:  \"To enable\n> > > anonymous read access but authenticated write access...\".  It\n> > > certainly sounds like what you want.\n> > > \n> > > Not sure what sort of http access you have setup \n> > \n> > I have \n> > \n> > ``````````\n> > <Location /git>\n> > AuthType Basic\n> > # Message to give to the committer\n> > AuthName \"Write access requires a password\"\n> > # File listing users with write (commit) access\n> > AuthUserFile /home/svn/PASSWD\n> > Require valid-user\n> > </Location>\n> > ``````````\n> > \n> > So authentication is require forman git-http-backend both read and write. Now to use one more level to restrict push user I have added one more restriction like\n> > \n> > <LocationMatch \"^/git/.*/ $\">\n> > AuthType Basic\n> > # Message to give to the committer\n> > AuthName \"Write access requires a password\"\n> > # File listing users with write (commit) access\n> > AuthUserFile /home/git/pushACL\n> > Require valid-user\n> > </LocationMatch>\n> > \n> > read access is working fine, but write access not. log reports \n> > \n> > ````````\n> >  user testuser not found: /git/web.git/info/refs\n> > ``````````\n> > \n> > Don't know why it is searching at /git/web.git/info/refs !!\n> > \n> \n> OK, seems the write authentication is checked twice. one for the first stanza for read access and second-time for the 2nd stanza the write access.\n> How can I tweak the first stanza only for read access ?\n\n\nJust like git-receive-pack anything for git pull,clone etc.. ? then we can use those to restrict read access separately. Users having read access need not have the right access then.\n"},{"id":"171658","messageId":"CAMK1S_hhHhETL2tE=E98Bku96KULC9L-pHCwz3iPjwEcMbCe9w@mail.gmail.com","threadId":"27852","inReplyTo":"20110719164037.05fd4a36@shiva.selfip.org","subject":"Re: Restricted git push ?","fromName":"Sitaram Chamarty","fromEmail":"sitaramc@gmail.com","sentAt":"2011-07-19T15:03:23Z","receivedAt":"2011-07-19T15:03:23Z","isPatch":false,"sender":{"key":"sitaramc@gmail.com","avatar":"https://avatars.githubusercontent.com/u/43316?v=4"},"body":"On Tue, Jul 19, 2011 at 4:40 PM, J. Bakshi <joydeep@infoservices.in> wrote:\n\n> Just like git-receive-pack anything for git pull,clone etc.. ? then we can use those to restrict read access separately. Users having read access need not have the right access then.\n\ngit-upload-pack I guess.  Maybe git-upload-archive also.\n\n-- \nSitaram\n"},{"id":"171718","messageId":"20110719213624.7be7b928@shiva.selfip.org","threadId":"27852","inReplyTo":"CAMK1S_hhHhETL2tE=E98Bku96KULC9L-pHCwz3iPjwEcMbCe9w@mail.gmail.com","subject":"Re: Restricted git push ?","fromName":"J. Bakshi","fromEmail":"joydeep@infoservices.in","sentAt":"2011-07-19T16:06:24Z","receivedAt":"2011-07-19T16:06:24Z","isPatch":false,"sender":{"key":"joydeep@infoservices.in","avatar":null},"body":"On Tue, 19 Jul 2011 20:33:23 +0530\nSitaram Chamarty <sitaramc@gmail.com> wrote:\n\n> On Tue, Jul 19, 2011 at 4:40 PM, J. Bakshi <joydeep@infoservices.in> wrote:\n> \n> > Just like git-receive-pack anything for git pull,clone etc.. ? then we can use those to restrict read access separately. Users having read access need not have the right access then.\n> \n> git-upload-pack I guess.  Maybe git-upload-archive also.\n> \n\nI have tried with git-upload-pack, but it gives error as\n\n````````````\nCloning into ....\nerror: RPC failed; result=22, HTTP code = 401\nfatal: The remote end hung up unexpectedly\n````````````````\n\nThe configuration I use is\n\n````````````\n<LocationMatch \"^/git/.*/git-upload-pack$\">\nAuthType Basic\n# Message to give to the committer\nAuthName \"Write access requires a password\"\n# File listing users with write (commit) access\nAuthUserFile /home/git/pushACL\nRequire valid-user\n</LocationMatch>\n````````````\n"}]}