- The signed LFS token carries the id of the SSH or deploy key that obtained it. A token without one (issued before this release) is refused.
- Every LFS request with a keyed token checks, before reading a body or serving an object, that the key exists, has not expired and its account is enabled (
store.LiveSSHKeys, the SSH sweep's query), and that it still has the access the operation needs (deploy scope and rw, or the account's role), including refusing an upload once the repository is archived. Anonymous tokens only download a repository that is public at request time. A refusal is a 404. - Tests for user and deploy keys, an e2e test, Threat-Model and Architecture pages, CHANGELOG with an upgrade note: a transfer in flight at deploy fails once; git-lfs asks for a new token on its next run.
Closes #285