e198dc489d2c335477932d1d02c06ff2885e31cd

Author
Toby Padilla <toby@charm.sh>
Committer
Toby Padilla <toby@charm.sh>
Date

Message

Don't allow cloning of `config` repo if anon isn't set to read-write

Diff

 1diff --git a/config/auth.go b/config/auth.go
 2index 1a772e27c27384e692d40d6be48cd147f9e62c09..879f694dda189fc7ebbae0a9490cc296b4842698 100644
 3--- a/config/auth.go
 4+++ b/config/auth.go
 5@@ -38,9 +38,14 @@ func (cfg *Config) accessForKey(repo string, pk ssh.PublicKey) gm.AccessLevel {
 6 					return gm.ReadWriteAccess
 7 				}
 8 			}
 9-			return gm.ReadOnlyAccess
10+			if repo != "config" {
11+				return gm.ReadOnlyAccess
12+			}
13 		}
14 	}
15+	if repo == "config" && (cfg.AnonAccess != "read-write") {
16+		return gm.NoAccess
17+	}
18 	switch cfg.AnonAccess {
19 	case "no-access":
20 		return gm.NoAccess