admin: explicit, audited override on repositories for moderation #71

closed cmc opened this on 2026-09-02 00:24 UTC · admin security · assigned to cmc · milestone v1.4.0

Discussion

cmc 2026-09-02 00:24 UTC

internal/policy/access.go has no IsAdmin clause, so an instance admin cannot archive, hide, or delete a spam repository, and no host-local command does it either.

Keep reads as they are so private repos still 404 to admins. For moderation add explicit commands that audit every use:

  • admin repo list [--owner] [--visibility] with size and last push (ListAllRepos already exists for gc and stats)
  • admin repo archive <owner/name>
  • admin repo visibility <owner/name> public|private
  • admin repo delete <owner/name> --yes

Do not make IsAdmin imply CanAdmin everywhere; the override should be visible in the audit log.

closed by commit 85a6c5a74e by cmc: admin: audited repository overrides for moderation

2026-09-02 01:13 UTC