threads / discuss / 29994

link user-name with ssh-login

Subject: link user-name with ssh-login

## tl;dr

5 messages between Mar 19, 2012 and Mar 21, 2012.

replies: 4people: 5as markdown or json

Roberto· Mar 19, 2012, 16:58 UTC · lore
Hi,

I have small ssh-based git server used for insite code development. But there is one thing I can't find how to set.

In the server, each developer has a valid ssh account (I switched the shell to git-shell). The problem is that when a developer commit's some code, he can freely set in his local .git/config file the user name he want's to appear in the commit logs. Is there any way to link/force a certain ssh login to a name?

Thanks,
Roberto
-- 
   -----------------------------------------------------
                 Marcos Roberto Greiner

    Os otimistas acham que estamos no melhor dos mundos
     Os pessimistas tem medo de que isto seja verdade
                                   James Branch Cabell
   -----------------------------------------------------
Junio C Hamano· Mar 19, 2012, 19:15 UTC · re: Roberto · lore

Re: link user-name with ssh-login

Roberto <mrgreiner@gmail.com> writes:
Show 8 quoted lines
> I have small ssh-based git server used for insite code
> development. But there is one thing I can't find how to set.
>
> In the server, each developer has a valid ssh account (I switched the
> shell to git-shell). The problem is that when a developer commit's
> some code, he can freely set in his local .git/config file the user
> name he want's to appear in the commit logs. Is there any way to
> link/force a certain ssh login to a name?

A pre-receive hook that lists the author names of the commits, along the lines of "git log --format='%an <%ae>' $OLD_HEAD..$NEW_HEAD" and compares against the name of the user authenticated against your SSH server would be a way to do this.

But that would mean you are forbidding people to accept patches from others, inspect the patches for validity and vouch for them, while giving the credit to them by recoding the author names of the patch authors.

Perhaps checking the committer name would suit your situation better. I dunno.

Jeff King· Mar 19, 2012, 20:57 UTC · re: Junio C Hamano · lore

Re: link user-name with ssh-login

On Mon, Mar 19, 2012 at 12:15:07PM -0700, Junio C Hamano wrote:
Show 11 quoted lines
> A pre-receive hook that lists the author names of the commits, along the
> lines of "git log --format='%an <%ae>' $OLD_HEAD..$NEW_HEAD" and compares
> against the name of the user authenticated against your SSH server would
> be a way to do this.
> 
> But that would mean you are forbidding people to accept patches from
> others, inspect the patches for validity and vouch for them, while giving
> the credit to them by recoding the author names of the patch authors.
> 
> Perhaps checking the committer name would suit your situation better.  I
> dunno.

Then you would be forbidding merges of other people's work, no? Even if the other person's commits are available in the upstream repo, they might be hitting this ref for the first time, and would be generally be checked by such a hook.

-Peff
Shawn Pearce· Mar 19, 2012, 21:56 UTC · re: Jeff King · lore

Re: link user-name with ssh-login

On Mon, Mar 19, 2012 at 13:57, Jeff King <peff@peff.net> wrote:
Show 18 quoted lines
> On Mon, Mar 19, 2012 at 12:15:07PM -0700, Junio C Hamano wrote:
>
>> A pre-receive hook that lists the author names of the commits, along the
>> lines of "git log --format='%an <%ae>' $OLD_HEAD..$NEW_HEAD" and compares
>> against the name of the user authenticated against your SSH server would
>> be a way to do this.
>>
>> But that would mean you are forbidding people to accept patches from
>> others, inspect the patches for validity and vouch for them, while giving
>> the credit to them by recoding the author names of the patch authors.
>>
>> Perhaps checking the committer name would suit your situation better.  I
>> dunno.
>
> Then you would be forbidding merges of other people's work, no? Even if
> the other person's commits are available in the upstream repo, they
> might be hitting this ref for the first time, and would be generally be
> checked by such a hook.

Most hooks that are trying to do this use "$NEW_HEAD --not --all" to only examine commits that would be newly reachable. Already reachable commits are presumed valid. If you want to merge someone else's commits, just make sure they have already pushed their commits to a branch somewhere, like a refs/heads/$USER/ sandbox space or something.

Sitaram Chamarty· Mar 21, 2012, 16:30 UTC · re: Roberto · lore

Re: link user-name with ssh-login

On Mon, Mar 19, 2012 at 10:28 PM, Roberto <mrgreiner@gmail.com> wrote:
Show 10 quoted lines
> Hi,
>
> I have small ssh-based git server used for insite code development. But
> there is one thing I can't find how to set.
>
> In the server, each developer has a valid ssh account (I switched the shell
> to git-shell). The problem is that when a developer commit's some code, he
> can freely set in his local .git/config file the user name he want's to
> appear in the commit logs. Is there any way to link/force a certain ssh
> login to a name?
along the lines of what others already said, here's my rant on this requirement:
https://github.com/sitaramc/gitolite/blob/pu/contrib/VREF/gl-VREF-EMAIL_CHECK#L37

← back to recent threads