git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Locked down (but still shared) repositories

From
Shawn Pearce <spearce@spearce.org>
Date
Dec 7, 2006, 19:17 UTC
Message-ID
<20061207191730.GA12143@spearce.org>
In-Reply-To
<Pine.LNX.4.63.0612071640160.28348@wbgn013.biozentrum.uni-wuerzburg.de>
Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:
Show 10 quoted lines
> On Thu, 7 Dec 2006, Shawn Pearce wrote:
> 
> > For various auditing reasons the repositories need to be tightly
> > controlled.  That is the following cannot be permitted:
> > 
> > [...]
> 
> How about just one such user? After all, you already have this user: the 
> repo owner. Of course, people have to push via ssh, even on the same 
> machine.

How do I know which SSH key the client used to connect? Remember I'm looking at the real uid to determine who is performing the operation. In the situation you describe everyone looks the same to the update hook...

For (probably stupid) reasons the server is the commerial F-Secure SSH server, btw. So OpenSSH based things wouldn't apply. And best that I can tell, F-Secure SSH won't tell me which key was used to authenticate.

Previous: Johannes SchindelinNext: Rogan Dawes
Message 4 of 8 in “Locked down (but still shared) repositories”
  1. Shawn PearceDec 7, 2006
  2. Martin WaitzDec 7, 2006
  3. Johannes SchindelinDec 7, 2006
  4. Shawn PearceDec 7, 2006
  5. Rogan DawesDec 7, 2006
  6. Shawn PearceDec 7, 2006
  7. Randal L. SchwartzDec 7, 2006
  8. Rogan DawesDec 7, 2006

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.