Page MenuHomePhabricator

Only require view permissions for read-only Git LFS requests
ClosedPublic

Authored by epriestley on Mar 19 2016, 6:11 PM.
Tags
None
Referenced Files
F15516992: D15499.id.diff
Fri, Apr 18, 10:53 PM
F15513163: D15499.diff
Thu, Apr 17, 4:58 PM
F15468495: D15499.id37362.diff
Fri, Apr 4, 1:03 AM
F15446257: D15499.diff
Thu, Mar 27, 6:01 PM
F15419319: D15499.diff
Fri, Mar 21, 5:16 AM
F15415697: D15499.id37362.diff
Thu, Mar 20, 7:30 AM
F15414024: D15499.id37361.diff
Mar 19 2025, 10:35 PM
F15409180: D15499.id37360.diff
Mar 19 2025, 3:33 AM
Subscribers
None

Details

Summary

Ref T7789. Implement proper detection for read-only requests. Previously, we assumed every request was read/write and required lots of permissions, but we don't need "Can Push" permission if you're only cloning/fetching/pulling.

Test Plan
  • Set push policy to "no one".
  • Fetched, got clean data out of LFS.
  • Tried to push, got useful error.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

epriestley retitled this revision from to Only require view permissions for read-only Git LFS requests.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: chad.
epriestley edited edge metadata.
  • Also do set_time_limit(0).
chad edited edge metadata.
This revision is now accepted and ready to land.Mar 19 2016, 9:22 PM
This revision was automatically updated to reflect the committed changes.