{"thread":{"id":"28542","subject":"Does git have \"Path-Based Authorization\"?","startedAt":"2011-09-30T23:43:28Z","lastAt":"2011-10-02T14:50:07Z","messageCount":15,"participants":["Grant","Carlos Martín Nieto","Nguyen Thai Ngoc Duy","david@lang.hm","Jakub Narebski","Sitaram Chamarty","Andreas Krey","Frans Klaver","Enrico Weigelt"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"176611","messageId":"CAN0CFw0QXkNSF8+qGu+pCrv5dgy1OEvtq-53f23GRd4RrZ1GcQ@mail.gmail.com","threadId":"28542","inReplyTo":null,"subject":"Does git have \"Path-Based Authorization\"?","fromName":"Grant","fromEmail":"emailgrant@gmail.com","sentAt":"2011-09-30T23:43:28Z","receivedAt":"2011-09-30T23:43:28Z","isPatch":false,"sender":{"key":"emailgrant@gmail.com","avatar":null},"body":"Hello, I'm trying to decide between git and subversion.  Subversion\nhas \"Path-Based Authorization\" so I can give a developer access to\nonly specific files instead of everything.  Does git have something\nsimilar?\n\nhttp://svnbook.red-bean.com/en/1.5/svn.serverconfig.pathbasedauthz.html\n\n- Grant\n"},{"id":"176614","messageId":"1317427503.4331.37.camel@centaur.lab.cmartin.tk","threadId":"28542","inReplyTo":"CAN0CFw0QXkNSF8+qGu+pCrv5dgy1OEvtq-53f23GRd4RrZ1GcQ@mail.gmail.com","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"Carlos Martín Nieto","fromEmail":"cmn@elego.de","sentAt":"2011-10-01T00:05:02Z","receivedAt":"2011-10-01T00:05:02Z","isPatch":false,"sender":{"key":"cmn@elego.de","avatar":"https://avatars.githubusercontent.com/u/335443?v=4"},"body":"On Fri, 2011-09-30 at 16:43 -0700, Grant wrote:\n> Hello, I'm trying to decide between git and subversion.  Subversion\n> has \"Path-Based Authorization\" so I can give a developer access to\n> only specific files instead of everything.  Does git have something\n> similar?\n\nGit's model does not allow the same type \"Path-Based Authorization\" that\nSubversion uses, because git uses secure hash sums to make sure that\npeople don't try to sneak changes into a pull request or merge, and you\ncan't selectively download parts of the tree because then you couldn't\ncheck that one of your remotes isn't trying to lie to you.\n\nYou can do something that is (or can be) similar with git and\ngitolite[0] so a developer (or set of developers) only has access to a\nparticular set of branches. Depending on what exactly you're trying to\ndo, this can be more or less complicated to set up. If you only want a\nset of developers to access the subdirectory\nclients/importantsecretclient, then you create that directory only in\nthe branch or branches that developer can read. There are many examples\nint he gitolite wiki.\n\n[0] https://github.com/sitaramc/gitolite/wiki/\n\nHTH\n\n   cmn\n\n"},{"id":"176616","messageId":"CAN0CFw0+v9qscJ+isQdwJOHT4Ajsk-96QK8gQFsu9E87a3j+Ww@mail.gmail.com","threadId":"28542","inReplyTo":"1317427503.4331.37.camel@centaur.lab.cmartin.tk","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"Grant","fromEmail":"emailgrant@gmail.com","sentAt":"2011-10-01T01:31:24Z","receivedAt":"2011-10-01T01:31:24Z","isPatch":false,"sender":{"key":"emailgrant@gmail.com","avatar":null},"body":">> Hello, I'm trying to decide between git and subversion.  Subversion\n>> has \"Path-Based Authorization\" so I can give a developer access to\n>> only specific files instead of everything.  Does git have something\n>> similar?\n>\n> Git's model does not allow the same type \"Path-Based Authorization\" that\n> Subversion uses, because git uses secure hash sums to make sure that\n> people don't try to sneak changes into a pull request or merge, and you\n> can't selectively download parts of the tree because then you couldn't\n> check that one of your remotes isn't trying to lie to you.\n>\n> You can do something that is (or can be) similar with git and\n> gitolite[0] so a developer (or set of developers) only has access to a\n> particular set of branches. Depending on what exactly you're trying to\n> do, this can be more or less complicated to set up. If you only want a\n> set of developers to access the subdirectory\n> clients/importantsecretclient, then you create that directory only in\n> the branch or branches that developer can read. There are many examples\n> int he gitolite wiki.\n\nI have a series of files containing server-side code which make up a\nwebsite.  The entire layout contains only a few folders, but those\nfolders contain many files.  I want to be able to allow access to only\ncertain files at a time, sometimes only a single file.  Can that be\ndone in the way you describe?\n\n- Grant\n\n\n> [0] https://github.com/sitaramc/gitolite/wiki/\n>\n> HTH\n>\n>   cmn\n"},{"id":"176617","messageId":"CACsJy8Dm-vSoki9Fr7s=DH7oRYL-a=kF7q9mBwo55ZxsLg5DTA@mail.gmail.com","threadId":"28542","inReplyTo":"CAN0CFw0+v9qscJ+isQdwJOHT4Ajsk-96QK8gQFsu9E87a3j+Ww@mail.gmail.com","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"Nguyen Thai Ngoc Duy","fromEmail":"pclouds@gmail.com","sentAt":"2011-10-01T01:34:12Z","receivedAt":"2011-10-01T01:34:12Z","isPatch":false,"sender":{"key":"pclouds@gmail.com","avatar":"https://avatars.githubusercontent.com/u/720?v=4"},"body":"On Sat, Oct 1, 2011 at 11:31 AM, Grant <emailgrant@gmail.com> wrote:\n> I have a series of files containing server-side code which make up a\n> website.  The entire layout contains only a few folders, but those\n> folders contain many files.  I want to be able to allow access to only\n> certain files at a time, sometimes only a single file.  Can that be\n> done in the way you describe?\n\nIf you can gather all sensitive files in a subdirectory, then you can\nsplit that directory into its own repository (see git-submodule man\npage) and grant limited access to that repo.\n-- \nDuy\n"},{"id":"176618","messageId":"CAN0CFw1-Edb5PdoTzJz38vJOjjXVAg6F24XgHpTi+3e5C7yxfQ@mail.gmail.com","threadId":"28542","inReplyTo":"CACsJy8Dm-vSoki9Fr7s=DH7oRYL-a=kF7q9mBwo55ZxsLg5DTA@mail.gmail.com","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"Grant","fromEmail":"emailgrant@gmail.com","sentAt":"2011-10-01T01:43:06Z","receivedAt":"2011-10-01T01:43:06Z","isPatch":false,"sender":{"key":"emailgrant@gmail.com","avatar":null},"body":">> I have a series of files containing server-side code which make up a\n>> website.  The entire layout contains only a few folders, but those\n>> folders contain many files.  I want to be able to allow access to only\n>> certain files at a time, sometimes only a single file.  Can that be\n>> done in the way you describe?\n>\n> If you can gather all sensitive files in a subdirectory, then you can\n> split that directory into its own repository (see git-submodule man\n> page) and grant limited access to that repo.\n> --\n> Duy\n\nI thought about separating files the dev has had access to into a\nseparate folder from files the dev hasn't had access to, but it would\nmean constantly changing the code as files move around, plus it would\nbe too complicated if I have multiple devs and want to give them\naccess to different stuff.  It's not that some files are more\nsensitive than others, it's just that I don't want to give anyone\naccess to more than I have to.\n\n- Grant\n"},{"id":"176619","messageId":"alpine.DEB.2.02.1109301904410.14711@asgard.lang.hm","threadId":"28542","inReplyTo":"CAN0CFw1-Edb5PdoTzJz38vJOjjXVAg6F24XgHpTi+3e5C7yxfQ@mail.gmail.com","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"","fromEmail":"david@lang.hm","sentAt":"2011-10-01T02:09:41Z","receivedAt":"2011-10-01T02:09:41Z","isPatch":false,"sender":{"key":"david@lang.hm","avatar":null},"body":"On Fri, 30 Sep 2011, Grant wrote:\n\n>>> I have a series of files containing server-side code which make up a\n>>> website.  The entire layout contains only a few folders, but those\n>>> folders contain many files.  I want to be able to allow access to only\n>>> certain files at a time, sometimes only a single file.  Can that be\n>>> done in the way you describe?\n>>\n>> If you can gather all sensitive files in a subdirectory, then you can\n>> split that directory into its own repository (see git-submodule man\n>> page) and grant limited access to that repo.\n>> --\n>> Duy\n>\n> I thought about separating files the dev has had access to into a\n> separate folder from files the dev hasn't had access to, but it would\n> mean constantly changing the code as files move around, plus it would\n> be too complicated if I have multiple devs and want to give them\n> access to different stuff.  It's not that some files are more\n> sensitive than others, it's just that I don't want to give anyone\n> access to more than I have to.\n\nthe thing to think about is why would you want to give a dev access to a \nfile or restrict their access.\n\nRemember that the Dev should be able to test their changes, so you really \nneed to give them access to enough stuff to be a complete, working set.\n\nIf you make each set of things it's own repository, then you should have \nthe granularity you are looking for.\n\nIf you think you will need more granularity, please explain what you are \nthinking of?\n\nAlso remember that you don't want to have your development files on your \nproduction site, so you probably don't want to deploy directly from your \nrepository to the production site. If you use a filter to make a new git \nrepository that only contains the pieces that you are wanting to publish, \nand keep that repository clean, only submitting the files that you want \nthere, but treat it as a read-only repository (i.e. no development work \ndone there), you should be in good shape.\n\nDavid Lang"},{"id":"176634","messageId":"m3lit4oo9q.fsf@localhost.localdomain","threadId":"28542","inReplyTo":"CAN0CFw0QXkNSF8+qGu+pCrv5dgy1OEvtq-53f23GRd4RrZ1GcQ@mail.gmail.com","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2011-10-01T13:06:19Z","receivedAt":"2011-10-01T13:06:19Z","isPatch":false,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"Grant <emailgrant@gmail.com> writes:\n\n> Hello, I'm trying to decide between git and subversion.  Subversion\n> has \"Path-Based Authorization\" so I can give a developer access to\n> only specific files instead of everything.  Does git have something\n> similar?\n> \n> http://svnbook.red-bean.com/en/1.5/svn.serverconfig.pathbasedauthz.html\n \nIn distributed version control systems each developers gets full copy\n(a clone) of a repository (separate repository instance).  This means that\nif you want for developer to see only specified subset of repository\n(specific subdirectories) you would have to split repository into\nsubmodules, and control access on (sub)repository basis.\n\n\nHowever if you want only to prevent developer from making changes outside\nspecific subdirectory or specified files, you can do that on publish time\nvia update / pre-receive hook (like contrib/hooks/update-paranoid), or git\nrepository management tool such as Gitolite.  That would prevent a push if\nany of commits being published touches files that it shouldn't.\n\nP.S. Karl Fogel in \"Producing Open Source Software\" (http://producingoss.com)\nwrites that social solutions wrt. restricting contributors to given area\nare better than technical solutions such as (overly-)strict access\ncontrol.\n\nHTH\n-- \nJakub Narębski\n"},{"id":"176668","messageId":"CAN0CFw3kzAgaVBKNHE5ttJgYnc_csjeHjOLq=EBjLizW=RPUkA@mail.gmail.com","threadId":"28542","inReplyTo":"m3lit4oo9q.fsf@localhost.localdomain","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"Grant","fromEmail":"emailgrant@gmail.com","sentAt":"2011-10-02T00:00:56Z","receivedAt":"2011-10-02T00:00:56Z","isPatch":false,"sender":{"key":"emailgrant@gmail.com","avatar":null},"body":">> Hello, I'm trying to decide between git and subversion.  Subversion\n>> has \"Path-Based Authorization\" so I can give a developer access to\n>> only specific files instead of everything.  Does git have something\n>> similar?\n>>\n>> http://svnbook.red-bean.com/en/1.5/svn.serverconfig.pathbasedauthz.html\n>\n> In distributed version control systems each developers gets full copy\n> (a clone) of a repository (separate repository instance).  This means that\n> if you want for developer to see only specified subset of repository\n> (specific subdirectories) you would have to split repository into\n> submodules, and control access on (sub)repository basis.\n\nI do want to prevent reading of all but one or a few specified files\nat a time.  I did some reading on the differences between centralized\nand distributed version control systems, and I can see how a\ndistributed system may be better for open source projects, but a\nbusiness project like mine may work better with centralized control.\nWould you guys agree in general?  Easier read/write control of\nindividual files in the repository is one benefit of the centralized\nmodel I will put to use.\n\n> However if you want only to prevent developer from making changes outside\n> specific subdirectory or specified files, you can do that on publish time\n> via update / pre-receive hook (like contrib/hooks/update-paranoid), or git\n> repository management tool such as Gitolite.  That would prevent a push if\n> any of commits being published touches files that it shouldn't.\n>\n> P.S. Karl Fogel in \"Producing Open Source Software\" (http://producingoss.com)\n> writes that social solutions wrt. restricting contributors to given area\n> are better than technical solutions such as (overly-)strict access\n> control.\n\nWhen I started this thread, I didn't realize the fact that my project\nis not open-source would help decide which version control system to\nuse.  Now I see that it does factor into the decision so I apologize\nfor not mentioning it previously.\n\n- Grant\n"},{"id":"176670","messageId":"CAMK1S_icdpCyA8SBcNu8CbCk3N-h8yEYZ9+6N=JVPAeayuzSPw@mail.gmail.com","threadId":"28542","inReplyTo":"CAN0CFw3kzAgaVBKNHE5ttJgYnc_csjeHjOLq=EBjLizW=RPUkA@mail.gmail.com","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"Sitaram Chamarty","fromEmail":"sitaramc@gmail.com","sentAt":"2011-10-02T01:27:57Z","receivedAt":"2011-10-02T01:27:57Z","isPatch":false,"sender":{"key":"sitaramc@gmail.com","avatar":"https://avatars.githubusercontent.com/u/43316?v=4"},"body":"On Sun, Oct 2, 2011 at 5:30 AM, Grant <emailgrant@gmail.com> wrote:\n>>> Hello, I'm trying to decide between git and subversion.  Subversion\n>>> has \"Path-Based Authorization\" so I can give a developer access to\n>>> only specific files instead of everything.  Does git have something\n>>> similar?\n>>>\n>>> http://svnbook.red-bean.com/en/1.5/svn.serverconfig.pathbasedauthz.html\n>>\n>> In distributed version control systems each developers gets full copy\n>> (a clone) of a repository (separate repository instance).  This means that\n>> if you want for developer to see only specified subset of repository\n>> (specific subdirectories) you would have to split repository into\n>> submodules, and control access on (sub)repository basis.\n>\n> I do want to prevent reading of all but one or a few specified files\n> at a time.  I did some reading on the differences between centralized\n> and distributed version control systems, and I can see how a\n> distributed system may be better for open source projects, but a\n> business project like mine may work better with centralized control.\n> Would you guys agree in general?  Easier read/write control of\n> individual files in the repository is one benefit of the centralized\n> model I will put to use.\n>\n>> However if you want only to prevent developer from making changes outside\n>> specific subdirectory or specified files, you can do that on publish time\n>> via update / pre-receive hook (like contrib/hooks/update-paranoid), or git\n>> repository management tool such as Gitolite.  That would prevent a push if\n>> any of commits being published touches files that it shouldn't.\n>>\n>> P.S. Karl Fogel in \"Producing Open Source Software\" (http://producingoss.com)\n>> writes that social solutions wrt. restricting contributors to given area\n>> are better than technical solutions such as (overly-)strict access\n>> control.\n>\n> When I started this thread, I didn't realize the fact that my project\n> is not open-source would help decide which version control system to\n> use.  Now I see that it does factor into the decision so I apologize\n> for not mentioning it previously.\n\nI'm afraid I did not follow the full thread, but I can assure you we\nhave several \"secret secret\" type projects at work, both mine as well\nas many others.\n\nThere are a few occasions when they need the kind of stuff you seem to\nwant more regularly, (the only one I can really recall is one of our\nlargest customers has a custom version of one of our product for\nthemselves and do not want people working on the generic version to\nsee those changes in case they propagate to their competitors).  We\njust do that by using a different repo entirely, and making sure\nchanges to common code migrate only one way.\n\nGit has too many advantages over legacy VCSs like SVN for people to\nthrow it over for something as simple as this.\n"},{"id":"176671","messageId":"CAN0CFw2gVH7=LdKhseE3zo+Av_=kVdz=tH3s=BKeTK9bDOprcw@mail.gmail.com","threadId":"28542","inReplyTo":"CAMK1S_icdpCyA8SBcNu8CbCk3N-h8yEYZ9+6N=JVPAeayuzSPw@mail.gmail.com","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"Grant","fromEmail":"emailgrant@gmail.com","sentAt":"2011-10-02T02:53:23Z","receivedAt":"2011-10-02T02:53:23Z","isPatch":false,"sender":{"key":"emailgrant@gmail.com","avatar":null},"body":">>>> Hello, I'm trying to decide between git and subversion.  Subversion\n>>>> has \"Path-Based Authorization\" so I can give a developer access to\n>>>> only specific files instead of everything.  Does git have something\n>>>> similar?\n>>>>\n>>>> http://svnbook.red-bean.com/en/1.5/svn.serverconfig.pathbasedauthz.html\n>>>\n>>> In distributed version control systems each developers gets full copy\n>>> (a clone) of a repository (separate repository instance).  This means that\n>>> if you want for developer to see only specified subset of repository\n>>> (specific subdirectories) you would have to split repository into\n>>> submodules, and control access on (sub)repository basis.\n>>\n>> I do want to prevent reading of all but one or a few specified files\n>> at a time.  I did some reading on the differences between centralized\n>> and distributed version control systems, and I can see how a\n>> distributed system may be better for open source projects, but a\n>> business project like mine may work better with centralized control.\n>> Would you guys agree in general?  Easier read/write control of\n>> individual files in the repository is one benefit of the centralized\n>> model I will put to use.\n>>\n>>> However if you want only to prevent developer from making changes outside\n>>> specific subdirectory or specified files, you can do that on publish time\n>>> via update / pre-receive hook (like contrib/hooks/update-paranoid), or git\n>>> repository management tool such as Gitolite.  That would prevent a push if\n>>> any of commits being published touches files that it shouldn't.\n>>>\n>>> P.S. Karl Fogel in \"Producing Open Source Software\" (http://producingoss.com)\n>>> writes that social solutions wrt. restricting contributors to given area\n>>> are better than technical solutions such as (overly-)strict access\n>>> control.\n>>\n>> When I started this thread, I didn't realize the fact that my project\n>> is not open-source would help decide which version control system to\n>> use.  Now I see that it does factor into the decision so I apologize\n>> for not mentioning it previously.\n>\n> I'm afraid I did not follow the full thread, but I can assure you we\n> have several \"secret secret\" type projects at work, both mine as well\n> as many others.\n>\n> There are a few occasions when they need the kind of stuff you seem to\n> want more regularly, (the only one I can really recall is one of our\n> largest customers has a custom version of one of our product for\n> themselves and do not want people working on the generic version to\n> see those changes in case they propagate to their competitors).  We\n> just do that by using a different repo entirely, and making sure\n> changes to common code migrate only one way.\n\nHow would something like that work in a case like mine where I have a\nseries of maybe 100 files and I only want to give my developer\nread/write access to one or a few files at a time with no read or\nwrite access to any of the other files?  Wouldn't setting up a\ndifferent repo for each set of files be difficult to manage?\n\n- Grant\n\n\n> Git has too many advantages over legacy VCSs like SVN for people to\n> throw it over for something as simple as this.\n"},{"id":"176672","messageId":"CACsJy8B2rhXvGKUsu10Po8cCi7p8uqWXWE5ZHB2Z6hH-aMyR2Q@mail.gmail.com","threadId":"28542","inReplyTo":"CAN0CFw2gVH7=LdKhseE3zo+Av_=kVdz=tH3s=BKeTK9bDOprcw@mail.gmail.com","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"Nguyen Thai Ngoc Duy","fromEmail":"pclouds@gmail.com","sentAt":"2011-10-02T03:24:32Z","receivedAt":"2011-10-02T03:24:32Z","isPatch":false,"sender":{"key":"pclouds@gmail.com","avatar":"https://avatars.githubusercontent.com/u/720?v=4"},"body":"On Sun, Oct 2, 2011 at 1:53 PM, Grant <emailgrant@gmail.com> wrote:\n> How would something like that work in a case like mine where I have a\n> series of maybe 100 files and I only want to give my developer\n> read/write access to one or a few files at a time with no read or\n> write access to any of the other files?  Wouldn't setting up a\n> different repo for each set of files be difficult to manage?\n\nThe write part is easy. Just setup hooks to reject updates on those\nfiles (however, notice the offline nature of git, people may commit\nlocally and the push later, you may need to check commit time on your\nhooks).\n\nThe reading part is hard, especially the way you put it (\"at a time\").\nThe only way I can think of is to not download those objects and try\nto fetch from central repo every time the objects are read,\nessentially turn git into a central scm again. Git does not support\nthis and may never do unless there's an reasonable use case.\n\nSo I have to ask, why do you do it this way? Once you give read-access\nto a developer, he/she can always save the files somewhere, revoking\nread access later on would be useless.\n-- \nDuy\n"},{"id":"176673","messageId":"CAN0CFw3ZDcXtD7WChjkT1Vg0cU_u==4KCHo8ff-ccbyxZ8xWjg@mail.gmail.com","threadId":"28542","inReplyTo":"CACsJy8B2rhXvGKUsu10Po8cCi7p8uqWXWE5ZHB2Z6hH-aMyR2Q@mail.gmail.com","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"Grant","fromEmail":"emailgrant@gmail.com","sentAt":"2011-10-02T03:34:43Z","receivedAt":"2011-10-02T03:34:43Z","isPatch":false,"sender":{"key":"emailgrant@gmail.com","avatar":null},"body":">> How would something like that work in a case like mine where I have a\n>> series of maybe 100 files and I only want to give my developer\n>> read/write access to one or a few files at a time with no read or\n>> write access to any of the other files?  Wouldn't setting up a\n>> different repo for each set of files be difficult to manage?\n>\n> The write part is easy. Just setup hooks to reject updates on those\n> files (however, notice the offline nature of git, people may commit\n> locally and the push later, you may need to check commit time on your\n> hooks).\n>\n> The reading part is hard, especially the way you put it (\"at a time\").\n> The only way I can think of is to not download those objects and try\n> to fetch from central repo every time the objects are read,\n> essentially turn git into a central scm again. Git does not support\n> this and may never do unless there's an reasonable use case.\n>\n> So I have to ask, why do you do it this way? Once you give read-access\n> to a developer, he/she can always save the files somewhere, revoking\n> read access later on would be useless.\n\nThat's true.  I hope to be able to give different developers access to\ndifferent parts of the code.  I really don't know if this will work.\nI just don't want my code to be stolen and I'm trying to find some way\nto prevent that from happening.\n\n- Grant\n"},{"id":"176679","messageId":"20111002063857.GA9385@inner.h.iocl.org","threadId":"28542","inReplyTo":"CAN0CFw3ZDcXtD7WChjkT1Vg0cU_u==4KCHo8ff-ccbyxZ8xWjg@mail.gmail.com","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"Andreas Krey","fromEmail":"a.krey@gmx.de","sentAt":"2011-10-02T06:38:57Z","receivedAt":"2011-10-02T06:38:57Z","isPatch":false,"sender":{"key":"a.krey@gmx.de","avatar":"https://avatars.githubusercontent.com/u/37810?v=4"},"body":"On Sat, 01 Oct 2011 20:34:43 +0000, Grant wrote:\n...\n> That's true.  I hope to be able to give different developers access to\n> different parts of the code.  I really don't know if this will work.\n\nDepending on the implementation it may drive away the good devs...\n\nAnyway, what I think you need (for the reasons detailed in the svn list)\nis a setup where the whole project is checked out in the staging area\nwhere it can be tested in whatever way. That under a user id different\nfrom the dev's. Then you change permissions so that he can only see\nand edit the files you want him to. This at least eases the problem\nof having to commit for each test, and gives you a meaningful history.\nAdditionally have sudo permissions to do commits etc. in the staging area.\n\n(But still the dev's life will be, erm, suboptimal.)\n\n> I just don't want my code to be stolen and I'm trying to find some way\n> to prevent that from happening.\n\nI'm just getting creative. When the one file that you allow access to\nis server-side code (as opposed to, say, css or client js) then the\nmalevolent dev can use that to read the rest of the staging area anyway.\n\nAndreas\n\n-- \n\"Totally trivial. Famous last words.\"\nFrom: Linus Torvalds <torvalds@*.org>\nDate: Fri, 22 Jan 2010 07:29:21 -0800\n"},{"id":"176680","messageId":"op.v2pox0g70aolir@keputer","threadId":"28542","inReplyTo":"CAN0CFw3ZDcXtD7WChjkT1Vg0cU_u==4KCHo8ff-ccbyxZ8xWjg@mail.gmail.com","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"Frans Klaver","fromEmail":"fransklaver@gmail.com","sentAt":"2011-10-02T06:43:02Z","receivedAt":"2011-10-02T06:43:02Z","isPatch":false,"sender":{"key":"fransklaver@gmail.com","avatar":"https://avatars.githubusercontent.com/u/1876483?v=4"},"body":"On Sun, 02 Oct 2011 05:34:43 +0200, Grant <emailgrant@gmail.com> wrote:\n\n> That's true.  I hope to be able to give different developers access to\n> different parts of the code.  I really don't know if this will work.\n> I just don't want my code to be stolen and I'm trying to find some way\n> to prevent that from happening.\n\nTo me it seems like you don't trust your developers? If you run a\nbusiness and you hire external developers, have them sign an NDA.\nShould be legally binding.\n\nI as a developer would be severely insulted if my boss tried to keep\nme away from some code, just because he was afraid it might get stolen.\n\nIf you don't trust them, fix your trust and relationship, not some tool.\n\nJust my two cents.\n\nHave a good one,\nFrans\n"},{"id":"176684","messageId":"20111002145007.GA15083@nibiru.local","threadId":"28542","inReplyTo":"op.v2pox0g70aolir@keputer","subject":"Re: Does git have \"Path-Based Authorization\"?","fromName":"Enrico Weigelt","fromEmail":"weigelt@metux.de","sentAt":"2011-10-02T14:50:07Z","receivedAt":"2011-10-02T14:50:07Z","isPatch":false,"sender":{"key":"weigelt@metux.de","avatar":null},"body":"* Frans Klaver <fransklaver@gmail.com> wrote:\n\nPutting on my business consultant hat:\n\n> If you don't trust them, fix your trust and relationship, not some tool.\n\nACK. We're essentially talking about a social/political problem,\nbot a technical one. Take my advise, solve the problem on the\nlayer it comes from.\n\nThe whole ideology of keeping individual devs on their little\ntiny isle is to have the whole project structured into such\nlittle islands in the first place. Meaning: a really strong\ncompartimentalization. This requires an strictly modular\narchitecture (which essentially means having completely\nseparate trees for the individual modules) and, of course,\ngood requirements engineering, contract-driven development,\netc, with all the associated role models, etc, etc.\n\nWhat kind of project are we talking about ?\nTactical control or nuclear plant systems ?\n\n\ncu\n-- \n----------------------------------------------------------------------\n Enrico Weigelt, metux IT service -- http://www.metux.de/\n\n phone:  +49 36207 519931  email: weigelt@metux.de\n mobile: +49 151 27565287  icq:   210169427         skype: nekrad666\n----------------------------------------------------------------------\n Embedded-Linux / Portierung / Opensource-QM / Verteilte Systeme\n----------------------------------------------------------------------\n"}]}