git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Permissions and authorisations in git repository

From
EWEnrico Weigelt <weigelt@metux.de>
Date
Jan 29, 2011, 17:28 UTC
Message-ID
<20110129172815.GB602@nibiru.local>
In-Reply-To
<20110128150631.33be0a9d.kostix@domain007.com>
* Konstantin Khomoutov <flatworm@users.sourceforge.net> wrote:
<snip>

In fact, git does not have any access control whatsoever. It relies on what the underlying transport protocol allows it to do.

With ssh, you could wrap the commands into some script which checks, the permissions on calling-in user or key (eg. restrict write access on certain refs to certain people). You could do even more fancy things like given everybody (or certain people) unrestricted write access, but under the hood put their rename the updated refs (eg. you can push 'master', but on the server, refs/heads/master wont be overwritten, instead it goes to refs/heads/konstantin/master).

Some people (coming from strictly-central ideologies) might consider git's access control angonsticity a drawback, but IMHO it's a very good thing - git doesn't want to be a full-blown "out-of-the-box" VCS (like, eg. clearcase), but more a lightweight toolkit to easily build your own.

cu
-- 
----------------------------------------------------------------------
 Enrico Weigelt, metux IT service -- http://www.metux.de/

 phone:  +49 36207 519931  email: weigelt@metux.de
 mobile: +49 151 27565287  icq:   210169427         skype: nekrad666
----------------------------------------------------------------------
 Embedded-Linux / Portierung / Opensource-QM / Verteilte Systeme
----------------------------------------------------------------------
Previous: Konstantin Khomoutov
Message 3 of 3 in “Permissions and authorisations in git repository”
  1. vikram2rhymeJan 28, 2011
  2. Konstantin KhomoutovJan 28, 2011
  3. Enrico WeigeltJan 29, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.