Re: git-http-backend and Authenticated Pushes
- From
BJ Hargrave <bj@bjhargrave.com>
- Date
- Mar 9, 2010, 19:17 UTC
- Message-ID
- <64E1366D-31FC-4E0D-9F7D-35E6387E2EC1@bjhargrave.com>
- In-Reply-To
- <2b8265361003091101x1e3a3410hc3be2446dc7ddce@mail.gmail.com>
On Mar 9, 2010, at 14:01 , Antonio García Domínguez wrote:
Show 7 quoted lines
> Git first GETs that URL you mention, and then POSTs to the usual > git-receive-pack URL. Both need authentication, but you're only > authenticating the POST. I suggest you authenticate every request to > the git-receive-pack service. Try something like this (warning, > untested!): > >> <LocationMatch "^/git/.*/[^/]*git-receive-pack$"
LocationMatch will not match against the query string which is where the service name is. To match against the query string, you would need to do something like:
RewriteCond %{QUERY_STRING} service=git-receive-pack
RewriteRule .* - [E=AUTHREQUIRED:yes]
then
Order Allow,Deny
Deny from env=AUTHREQUIRED
Allow from all
Satisfy Any
# Add other auth statements for password file.(also untested :-)
But, I would think using <LimitExcept GET PROPFIND OPTIONS REPORT> to protect against "writing" to the repo without auth should be sufficient.
-- BJ Hargrave