Commit fad7a633f4
Verified · cmc
Layout: unified · split
CHANGELOG.org +13 −12
| @@ -9,8 +9,9 @@ anything beyond "replace the binary and restart" is needed. | ||
| 9 | 9 | - =webhook add= reads the signing secret from stdin with =--secret -=; |
| 10 | 10 | a value on the command line is refused, since argv shows in process |
| 11 | 11 | listings and shell history. A script that passed the value must pipe |
| 12 | it: =printf %s "$SECRET" | gitbay webhook add <repo> <url> --secret -= | |
| 13 | (#284). | |
| 12 | it: =printf %s "$SECRET" | gitbay webhook add <repo> <url> --secret -=. | |
| 13 | The iOS app's webhook add breaks until it sends the secret on stdin | |
| 14 | (krz/gitbay-ios#21) (#284). | |
| 14 | 15 | - =repo import --from= takes http and https URLs only; =git://= is |
| 15 | 16 | refused, since its connection cannot be held to a checked address. |
| 16 | 17 | The host is resolved and checked like a mirror's, git connects only |
| @@ -18,15 +19,6 @@ anything beyond "replace the binary and restart" is needed. | ||
| 18 | 19 | global gitconfig are ignored. A source that redirects (a renamed |
| 19 | 20 | repository) fails; import from the URL it redirects to. Needs git |
| 20 | 21 | 2.37 or later on the server (#298). |
| 21 | *Upgrade note.* =repo import= and mirror sync now refuse a =git://= | |
| 22 | source and a =--from=/remote URL carrying a query or fragment. A | |
| 23 | mirror or import whose host is written numerically (=127.1=, | |
| 24 | =2130706433=, =0x7f.1=) rather than as a dotted address is refused | |
| 25 | too; rewrite it before upgrading. | |
| 26 | - A web session older than 15 minutes cannot mint a credential or grant | |
| 27 | access — keys, PGP keys, tokens, org membership, and the admin | |
| 28 | promote/enable actions — and the form it tried shows a sign-in link | |
| 29 | that returns there (#297). | |
| 30 | 22 | - A browser session creates credentials and grants access — keys, PGP |
| 31 | 23 | keys, tokens, verified addresses, org and repository roles, transfers, |
| 32 | 24 | webhooks, secrets, mirrors, and the admin promote/enable actions — |
| @@ -95,6 +87,12 @@ entries; if extracting one leaves a repository's =refs/= directory | ||
| 95 | 87 | missing, =gitbayd admin backup --verify <archive>= names it, and |
| 96 | 88 | =mkdir -p <root>/repos/<owner>/<name>.git/refs= fixes it. |
| 97 | 89 | |
| 90 | *Upgrade note.* =repo import= now refuses a =git://= source and a | |
| 91 | =--from= URL carrying a query or fragment. Mirrors and imports whose | |
| 92 | host is written numerically (=127.1=, =2130706433=, =0x7f.1=) rather | |
| 93 | than as a dotted address are refused too; rewrite the URL before | |
| 94 | upgrading (#298). | |
| 95 | ||
| 98 | 96 | - A token with a =--ttl= is refused on every command that creates a |
| 99 | 97 | credential: tokens, keys, deploy keys, runner keys, login links, |
| 100 | 98 | invites, accounts and verified addresses (#257). |
| @@ -294,7 +292,10 @@ missing, =gitbayd admin backup --verify <archive>= names it, and | ||
| 294 | 292 | hour (#285). *Operators:* tokens minted before the upgrade are |
| 295 | 293 | refused. git-lfs asks =git-lfs-authenticate= for a token each time |
| 296 | 294 | it runs, so only a transfer running across the restart fails, with |
| 297 | "repository not found"; running the command again fixes it. | |
| 295 | "repository not found"; running the command again fixes it. A | |
| 296 | download from a public repository that presents a token issued | |
| 297 | before the upgrade is refused the same way, not served anonymously, | |
| 298 | and needs the same rerun. | |
| 298 | 299 | - Every LFS request also repeats the repository check for the token's |
| 299 | 300 | key: a collaborator whose access is revoked or reduced, or a reader |
| 300 | 301 | of a public repository made private, loses the token's use with the |