From: Matthias Urlichs Date: Tue, 27 Sep 2005 08:45:13 GMT Subject: Re: shared GIT repos Message-ID: <20050927084513.GU31276@kiste.smurf.noris.de> In-Reply-To: <7vu0g70yqg.fsf_-_@assigned-by-dhcp.cox.net> Hi, Junio C Hamano: > Do you want to guard the repository from malicious users? Or is > it enough to guard a casual/careless user from making mistakes? > Well, s/malicious users/somebody who wants to cover up an ugly mistake/ would be more accurate. What I am doing: I'm writing a system management frontend which allows people to install version-controlled stuff (like, the configuration for a backup server, or Yet Another PHPBB Installation) on servers -- without even having a login there. Some of these contain login scripts that might need root privileges or similar (like, "restart Apache"). I want people to be unable to simply remove the commit that included the "rm -rf /" command, move the ref back, upload a new version, and pretend that nothing happened *la la la*. > If one has commit privileges, then one can already do enough > harm to the project without being able to remove objects nor > updating a ref with non-fast-forward ref. But in that case it's traceable what happened and whodunit. > I think most of the pieces are already there and you only need to > assemble them and write a howto ;-). > [ list ] OK, thanks, that helps. I'll write something up. -- Matthias Urlichs | {M:U} IT Design @ m-u-it.de | smurf@smurf.noris.de Disclaimer: The quote was selected randomly. Really. | http://smurf.noris.de - - When angry, count four; when very angry, swear.