git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Question: Setting the Email Address in ~/.gitconfig

From
SMShreya Malviya <shreya.malviya@gmail.com>
Date
Jun 11, 2020, 21:25 UTC
Message-ID
<CAEqpqjGNANrCX0wMDUP+dZ+_PdMveSJf6XFyiCpJdUH5t6jXvw@mail.gmail.com>
Hi!

I was playing around with git when I realized that it's possible for me to commit something to a repository as another user (explained a scenario below for a better understanding of what I mean) and it is not considered a security vulnerability, understandably so (https://bounty.github.com/ineligible.html#impersonating_a_user_through_git_email_address).

For example, let's assume I have push access to some repository called AAA, and my email address is abc@xyz.com. I can simply edit ~/.gitconfig on my system and set the email address as some other person's email address: def@pqr.com. Then, I make some changes in my local repository and commit them (reminder: it's with the email address def@pqr.com since git tracks commits by email address). Now, if I try to push to the remote repository, it asks for the username and password. I put mine and since I have push access to AAA, it goes through. I've successfully pushed commits on behalf of the owner of the email address: def@pqr.com.

So basically, in this way, I can impersonate people and add commits on their behalf. BUT AGAIN, this is not considered a vulnerability (link for reason attached before).

My question: It would be much easier if git didn't allow changing the email address so easily. Why hasn't git implemented OAuth, or something of that sort, for every time that the email address is changed in ~/.gitconfig, yet?

Shreya Malviya
Next: brian m. carlson
Message 1 of 3 in “Question: Setting the Email Address in ~/.gitconfig”
  1. Shreya MalviyaJun 11, 2020
  2. brian m. carlsonJun 11, 2020
  3. Aaron SchrabJun 13, 2020

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.