Commit 273e9b95f8

273e9b95f8b87ee2be442c6bff6cbffbfd09cccf

parent: ab95b83440

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-29 02:15 UTC

wiki: web mints and grants need a sign-in from the last 15 minutes

Closes #297

Layout: unified · split

.gitbay/wiki/Architecture/05-Identity-and-Access.org +12 −1
@@ -18,7 +18,7 @@
1818| SSH user key | user's public key | fingerprint and public blob | =full=, =git=, or =runner= | optional =--ttl=, refused at auth | =keys remove= (own keys); closes its connections |
1919| Deploy key | public key | same table, scope =deploy:<repo>:ro/rw= | one repository, read or read-write | optional =--ttl=, refused at auth | =repo deploy-key remove= (repo admin); closes its connections |
2020| API token | =gb_= + 32 random bytes hex | SHA-256 hash | =read= (default) or =full=; with an expiry, no credential-minting command | optional =--ttl= | =token revoke [--created]= |
21| Web session | 32 random bytes hex, cookie =gitbay_session= | SHA-256 hash | full account | 12 h idle, 7 days absolute | logout, =web sessions revoke= |
21| Web session | 32 random bytes hex, cookie =gitbay_session= | SHA-256 hash | full account; credential-minting and access-granting commands only within 15 minutes of sign-in | 12 h idle, 7 days absolute | logout, =web sessions revoke= |
2222| Login link | 32 random bytes hex in a URL | SHA-256 hash, single use | creates a web session | 15 min (mail), 5 min (SSH) | consumed on use |
2323| Email verification | 32 random bytes hex | SHA-256 hash, single use | verifies one address for one account | 24 h | consumed on use |
2424| Invite | random code | SHA-256 hash, single use | one registration for one email | as issued | consumed on use |
@@ -118,6 +118,17 @@ button and the displayed status (=internal/control/mr.go=):
118118- Destructive web actions (key, email and PGP removal, release, snippet,
119119 team and label deletion, user disable and demote) require the target's
120120 name typed into the form (=internal/httpd/confirm.go=).
121- Commands that create a credential (SSH, deploy and runner keys, API
122 tokens, email verification, login links, PGP keys, device tokens) or
123 grant access (repository and organization roles, teams, transfers,
124 admin promote and enable, webhooks, secrets, mirrors) are refused
125 from a browser session that signed in more than 15 minutes ago
126 (=control.ReauthWindow=, =Command.NeedsRecentSignIn=). The sign-in
127 time is =web_sessions.created_at=, which idle renewal does not move;
128 a request with no sign-in time is refused. SSH, API tokens and host
129 commands are unaffected. The refusal is audited; the form shows it
130 with a sign-in link, and the login returns to the page through the
131 server-set =gitbay_next= cookie (=internal/httpd/flash.go=).
121132
122133* Rate limits
123134
.gitbay/wiki/Architecture/09-Controls.org +1 −1
@@ -26,7 +26,7 @@ chapter names of OWASP ASVS 4.0 where one fits.
2626| Session lifetime | in place | 12 hours idle, 7 days absolute (=internal/store/sessions.go=) |
2727| Credential expiry | in place | optional =--ttl= on API tokens, SSH and deploy keys; checked at auth and per exec |
2828| Revocation takes effect immediately | in place | removing a key or disabling an account closes its connections; every exec re-reads its key (=internal/sshd/sshd.go=); LFS transfer tokens are refused with their key (=internal/httpd/lfs.go=) |
29| Delegation bounded by the delegating credential | partial | expiring tokens refused on =MintsCredential= commands; credentials record their creating token (=internal/control/control.go=); a web session can still mint credentials that outlive it (#297) |
29| Delegation bounded by the delegating credential | in place | expiring tokens refused on =MintsCredential= commands; credentials record their creating token; a browser session runs credential-minting and access-granting commands only within 15 minutes of signing in, and the refusal is audited (=internal/control/control.go=) |
3030
3131** Access control (V4)
3232
.gitbay/wiki/Architecture/10-Known-Gaps.org −2
@@ -13,8 +13,6 @@ what the 2026-09-27 review found; remove a row when its issue closes.
1313| #259 | Recovery | No restore has been exercised; the drill is written (Admin wiki) and not yet run | high |
1414| #260 | CI network | Builds share the runner's source address; no egress policy | medium |
1515| #261 | Various | Migration foreign-key check after commit; three web writes bypass dispatch; documentation drift | medium |
16| #297 | Credentials | A browser session can mint tokens and keys that outlive it | low |
17| #301 | SSRF | =repo import-issues --api-base= fetches without an address check or pin | medium |
1816
1917* Not filed
2018
.gitbay/wiki/Threat-Model.org +3 −2
@@ -61,8 +61,9 @@ matrix and the open gaps are in the [[file:Architecture/00-Overview.org][Archite
6161 rights narrowed by its credential's scope, decided in one place, so a
6262 bearer token is worth exactly its scope and no more, and a token or
6363 SSH key with an expiry cannot create a credential that outlives it.
64 Browser sessions are not covered yet (#297). Git transport never runs
65 over the API.
64 A browser session can create one, or grant access, only within 15
65 minutes of signing in (=control.ReauthWindow=, #297). Git transport
66 never runs over the API.
6667- *Anonymous surfaces* — HTTPS clone of public repos, =git://= where
6768 enabled, the read-only web UI — carry no credentials and expose only
6869 public data. HTTP push is refused via a pkt-line =ERR=, never a 401.
.gitbay/wiki/Users.org +6
@@ -701,6 +701,12 @@ creation, expiry and last use, and =gitbay web sessions revoke <id>=
701701or =--all= ends them from the terminal, which is where a lost laptop is
702702handled.
703703
704Actions that create a credential or grant access (adding a key, token
705or email, org and repository roles, transfers) ask you to sign in again
706when your web sign-in is older than 15 minutes. The form shows a "Sign
707in again" link and the login returns to the page. Idle renewal does not
708extend this window.
709
704710=web theme set light= or =dark= fixes the web UI's colour scheme for
705711your account; =system=, the default, follows the browser's own
706712preference. =web theme show= prints it. The account page has the same
CHANGELOG.org +6
@@ -27,6 +27,12 @@ too; rewrite it before upgrading.
2727 access — keys, PGP keys, tokens, org membership, and the admin
2828 promote/enable actions — and the form it tried shows a sign-in link
2929 that returns there (#297).
30- A browser session creates credentials and grants access — keys, PGP
31 keys, tokens, verified addresses, org and repository roles, transfers,
32 webhooks, secrets, mirrors, and the admin promote/enable actions —
33 only within 15 minutes of signing in. An older session gets the form
34 back with a "Sign in again" link, and the login returns to it. SSH and
35 API tokens are unaffected (#297).
3036- The builds page's status badge section gives an org-mode snippet
3137 beside the Markdown one, for a README.org (#299).
3238- API tokens on the settings page: create with a scope and optional