Commit 39f6887
committed
fix: enforce provider ID (type/host) consistently across both proxy modes
Provider IDs must be `type/host` everywhere (e.g. `forgejo/gitea`,
`github/github.com`). Previously bare type names (`gitea`, `github`) were
accepted in YAML config, stored in rules/permissions, and returned from
APIs, causing identity resolution and access rule failures.
Changes:
- RepositoryUrlRuleHook: replace stub (always-pass) with full deny/allow
rule evaluation matching UrlRuleAggregateFilter behaviour; S&F mode now
enforces URL rules
- StoreAndForwardReceivePackFactory: accept and wire UrlRuleFilter list +
RepoRegistry so the hook can evaluate config and DB rules
- GitProxyServletRegistrar: build URL rule filters for S&F path and pass
alongside registry to the factory
- JettyConfigurationBuilder: validate provider IDs in rules, permissions,
and scm-identities at startup (crash on unknown ID); use getProviderId()
instead of getName() in rule filter construction; cache provider list
- UrlRuleFilter: add matchesRepo() for rule evaluation without HttpServletRequest
- UrlRuleAggregateFilter: fix recordFetch to store getProviderId() not URI host
- ProviderController: add `id` (type/host) field to ProviderInfo response
- RepoController: validate provider ID on createRule/updateRule; use stored
provider field (not URL hostname) for active repos aggregation
- PushController: drop redundant ROLE_SELF_CERTIFY Spring authority check;
isBypassReviewAllowed() is sufficient and was already enforcing the grant
- AuthController: dynamically add ROLE_SELF_CERTIFY to /api/me response
when the user has any SELF_CERTIFY permission grant (fixes UI self-certify)
- Frontend dropdowns (Profile, UserDetail, Repos): submit provider ID (p.id)
as value, display hostname (p.host) as label
- YAML configs: update all provider references to type/host format
(gitea → forgejo/gitea, github → github/github.com)
- Delete InMemoryFilterConfigurationSource (dead code)
- Tests: update RepoControllerTest for new validation; add
IdentityVerificationMode coverage tests
closes #941 parent 0c6222b commit 39f6887
24 files changed
Lines changed: 481 additions & 197 deletions
File tree
- docker
- git-proxy-java-core/src
- main/java/org/finos/gitproxy
- config
- git
- servlet/filter
- test/java/org/finos/gitproxy/config
- git-proxy-java-dashboard
- frontend/src
- pages
- src
- main/java/org/finos/gitproxy/dashboard/controller
- test/java/org/finos/gitproxy/dashboard/controller
- git-proxy-java-server/src/main
- java/org/finos/gitproxy/jetty
- config
- resources
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
| 24 | + | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
32 | | - | |
| 32 | + | |
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
39 | 39 | | |
40 | | - | |
| 40 | + | |
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
| |||
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
50 | | - | |
| 50 | + | |
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
55 | 55 | | |
56 | | - | |
| 56 | + | |
57 | 57 | | |
58 | 58 | | |
59 | 59 | | |
60 | 60 | | |
61 | 61 | | |
62 | 62 | | |
63 | | - | |
| 63 | + | |
64 | 64 | | |
65 | 65 | | |
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
69 | 69 | | |
70 | | - | |
| 70 | + | |
71 | 71 | | |
72 | 72 | | |
73 | 73 | | |
74 | | - | |
| 74 | + | |
75 | 75 | | |
76 | 76 | | |
77 | 77 | | |
78 | 78 | | |
79 | | - | |
| 79 | + | |
80 | 80 | | |
81 | 81 | | |
82 | 82 | | |
83 | 83 | | |
84 | | - | |
| 84 | + | |
85 | 85 | | |
86 | 86 | | |
87 | 87 | | |
88 | 88 | | |
89 | 89 | | |
90 | | - | |
| 90 | + | |
91 | 91 | | |
92 | 92 | | |
93 | 93 | | |
94 | | - | |
| 94 | + | |
95 | 95 | | |
96 | 96 | | |
97 | 97 | | |
| |||
153 | 153 | | |
154 | 154 | | |
155 | 155 | | |
156 | | - | |
| 156 | + | |
157 | 157 | | |
158 | 158 | | |
159 | 159 | | |
| |||
163 | 163 | | |
164 | 164 | | |
165 | 165 | | |
166 | | - | |
| 166 | + | |
167 | 167 | | |
168 | 168 | | |
169 | 169 | | |
170 | 170 | | |
171 | 171 | | |
172 | 172 | | |
173 | 173 | | |
174 | | - | |
| 174 | + | |
175 | 175 | | |
176 | 176 | | |
177 | 177 | | |
| |||
185 | 185 | | |
186 | 186 | | |
187 | 187 | | |
188 | | - | |
| 188 | + | |
189 | 189 | | |
190 | 190 | | |
191 | 191 | | |
| |||
196 | 196 | | |
197 | 197 | | |
198 | 198 | | |
199 | | - | |
| 199 | + | |
200 | 200 | | |
201 | 201 | | |
202 | 202 | | |
| |||
208 | 208 | | |
209 | 209 | | |
210 | 210 | | |
211 | | - | |
| 211 | + | |
212 | 212 | | |
213 | 213 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
32 | | - | |
| 32 | + | |
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
| 20 | + | |
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
| 24 | + | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
48 | | - | |
| 48 | + | |
49 | 49 | | |
50 | 50 | | |
51 | 51 | | |
| |||
57 | 57 | | |
58 | 58 | | |
59 | 59 | | |
60 | | - | |
| 60 | + | |
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
64 | | - | |
| 64 | + | |
65 | 65 | | |
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
69 | | - | |
| 69 | + | |
70 | 70 | | |
71 | 71 | | |
72 | 72 | | |
73 | | - | |
| 73 | + | |
74 | 74 | | |
75 | 75 | | |
76 | 76 | | |
git-proxy-java-core/src/main/java/org/finos/gitproxy/config/InMemoryFilterConfigurationSource.java
Lines changed: 0 additions & 34 deletions
This file was deleted.
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
177 | 177 | | |
178 | 178 | | |
179 | 179 | | |
180 | | - | |
| 180 | + | |
181 | 181 | | |
182 | 182 | | |
183 | 183 | | |
| |||
0 commit comments