git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] push: deny policy to prevent pushes to unwanted remotes.

From
AQAntoine Queru <antoine.queru@ensimag.grenoble-inp.fr>
Date
Jun 6, 2016, 14:00 UTC
Message-ID
<1589200049.381440.1465221656049.JavaMail.zimbra@ensimag.grenoble-inp.fr>
In-Reply-To
<C7CBA69F-64BC-4710-8FF7-5CDC2A59E1E5@gmail.com>
Hello Lars, thanks for your reply. 
Show 37 quoted lines
> 
> 
> > On 30 May 2016, at 06:45, Antoine Queru
> > <antoine.queru@ensimag.grenoble-inp.fr> wrote:
> > 
> > Currently, a user wanting to prevent accidental pushes to the wrong remote
> > has to create a pre-push hook.
> > The feature offers a configuration to allow users to prevent accidental
> > pushes
> > to the wrong remote. The user may define a list of whitelisted remotes, a
> > list
> > of blacklisted remotes and a default policy ("allow" or "deny"). A push
> > is denied if the remote is explicitely blacklisted or if it isn't
> > whitelisted and the default policy is "deny".
> > 
> > This feature is intended as a safety net more than a real security, the
> > user
> > will always be able to modify the config if he wants to. It is here for him
> > to
> > consciously restrict his push possibilities. For example, it may be useful
> > for an unexperimented user fearing to push to the wrong remote, or for
> > companies wanting to avoid unintentionnal leaking of private code on public
> > repositories.
> 
> Thanks for working on this feature. Unfortunately I won't be able to test and
> review it before June 14. I am traveling without laptop and only very
> sporadic internet access :)
> 
> One thing that I noticed already: I think a custom warning/error message for
> rejected pushes would be important because, as you wrote above, this feature
> does not provide real security. That means if a push is rejected for someone
> in an organization then the user needs to understand what is going on. E.g.
> in my organization I would point the user to the open source contribution
> guidelines etc.
> 
> Thanks,
> Lars

I might not understand what you've said, but I think this feature is already implemented in our version, with remote.pushDenyMessage. Is this what you're talking about ?

Previous: Lars SchneiderNext: Lars Schneider
Message 5 of 6 in “push: deny policy to prevent pushes to unwanted remotes.”
  1. push: deny policy to prevent pushes to unwanted remotes.Antoine Queru, May 30, 2016
  2. Matthieu MoyMay 30, 2016
  3. Francois BeutinMay 30, 2016
  4. Lars SchneiderJun 2, 2016
  5. Antoine QueruJun 6, 2016
  6. Lars SchneiderJun 15, 2016

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.