Re: Git and securing a repository
- From
Jakub Narebski <jnareb@gmail.com>
- Date
- Jan 2, 2008, 10:51 UTC
- Message-ID
- <m3ir2co5s4.fsf@roke.D-201>
- In-Reply-To
- <477B69ED.3090107@advancedsl.com.ar>
Gonzalo Garramuño <ggarra@advancedsl.com.ar> writes:
Show 11 quoted lines
> David Symonds wrote: >> >> You can do arbitrarily-fine-grained authentication via the >> pre-receive hook. >> > > Can you provide some more info? Looking at the kernel.org git docs, > the pre-receive hook seems very limited as no parameters are allowed. > So I'm not sure how an authentication system could be created. > > It also seems to be a push hook only (not invoked on pulls).
Some of read-only (fetch only) access protocols do not support authentication: http, ftp, rsync, git. Authentication is provided only for access via ssh and for push via https (WebDAV).
There is example update hook in contrib/hooks, named update-paranoid, which could be base of what you want. Note that you probably rather use newer pre-receive hook instead of older update hook.
AFAIK both update and pre-receive hooks are invoked also on fetch... but I might be mistaken.
-- Jakub Narebski Poland ShadeHawk on #git