tests: a private repository is invisible on every surface, in one test !247

merged merged by cmc on 2026-09-04 19:38 UTC · krz/gitbay:security-sweep into main

Discussion

cmc

From the security sweep (#149).

The threat model states private-repo invisibility as one cross-cutting rule, but it was tested per feature — so a surface added later leaks and nothing fails. TestPrivateRepoIsInvisible makes the list of surfaces the thing under test: every web route, thirteen control commands, and the listings a stranger legitimately reaches, as both anonymous and logged-in.

Two things worth knowing about the test itself:

  • It distinguishes a leak from an echo. A search page renders the query into its form and filter links, so a term present because the prober typed it proves nothing. My first version didn't make that distinction and reported four false positives; I confirmed they were false by checking whether the page linked the repo or showed the issue title, and it did neither.
  • It's load-bearing. Removing the visibility predicate from the search query fails it on both the web and CLI paths.

The sweep also confirmed the headers, parser fuzzing, #+INCLUDE: refusal, LFS/asset path handling and org/team authorization are all sound, and found two things that are not — #147 and #148.

Ref #149