Re: Push Certificates: Privacy Concerns Regarding the "pushee" Header
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Feb 18, 2026, 06:00 UTC
- Message-ID
- <xmqqo6lm8ubv.fsf@gitster.g>
- In-Reply-To
- <19c5dd32-6752-43fa-a664-5e6d29d9e681@posteo.eu>
Lorenz Leutgeb <lorenz.leutgeb@posteo.eu> writes:
> Now, in the context of the application, the global identifier of the > repository across the network, and thus the pushee that I would like to > see, is `example://foo`. The path `home/lorenz.example/storage/foo` is > merely a local name for it, like a cached copy if you will.
"The repo appears as X to me, but it is known as Y to others" is an issue that already exists. "git pull" records from which repository the changes were merged but it uses the repository from the point of the view of the user who ran "git pull", for example. While one of my public repositories are known as https://github.com/gitster/git", the URL I use to push there may be "git@github.com:gitster/git.git", so if they were recording push certificates, the latter would be the pushee in them, but that is not a URL random people can normally use to clone from.