mirror of
https://github.com/go-gitea/gitea.git
synced 2026-08-08 17:07:43 +00:00
fix(lfs): require proof of possession for cross-repo objects (#38322)
The LFS batch and upload handlers linked an object that already existed in the content store but was not linked to the current repo whenever the token's user could access it in another repo. Deploy-key tokens carry the repo owner's identity, so a single-repo write deploy key could link and then download objects from any repo the owner can see. This drops the cross-repo access check: the batch handler now makes the client upload (hash-verified) any object not yet linked to the repo, and the upload handler skips proof of possession only when the object is already linked to the current repo.
This commit is contained in:
@@ -240,9 +240,14 @@ func TestAPILFSBatch(t *testing.T) {
|
||||
assert.Equal(t, "Size must be less than or equal to 2", br.Objects[0].Error.Message)
|
||||
})
|
||||
|
||||
t.Run("AddMeta", func(t *testing.T) {
|
||||
t.Run("CrossRepoObjectRequiresUpload", func(t *testing.T) {
|
||||
defer tests.PrintCurrentTest(t)()
|
||||
|
||||
// An object whose bytes already exist in the store but which is not
|
||||
// linked to this repo must not be silently linked, even when the
|
||||
// caller can access it in another repo. Auto-linking let a deploy key
|
||||
// (whose token carries the repo owner's identity) exfiltrate objects
|
||||
// across repos without proving possession. The client must upload.
|
||||
p := lfs.Pointer{Oid: "05eeb4eb5be71f2dd291ca39157d6d9effd7d1ea19cbdc8a99411fe2a8f26a00", Size: 6}
|
||||
|
||||
contentStore := lfs.NewContentStore()
|
||||
@@ -250,6 +255,7 @@ func TestAPILFSBatch(t *testing.T) {
|
||||
assert.NoError(t, err)
|
||||
assert.True(t, exist)
|
||||
|
||||
// The object is linked to another repo owned by the same user.
|
||||
repo2 := createLFSTestRepository(t, "lfs-batch2-repo")
|
||||
storeObjectInRepo(t, repo2.ID, "dummy0")
|
||||
|
||||
@@ -266,11 +272,13 @@ func TestAPILFSBatch(t *testing.T) {
|
||||
br := decodeResponse(t, resp.Body)
|
||||
assert.Len(t, br.Objects, 1)
|
||||
assert.Nil(t, br.Objects[0].Error)
|
||||
assert.Empty(t, br.Objects[0].Actions)
|
||||
// The client is told to upload instead of the object being linked.
|
||||
assert.Contains(t, br.Objects[0].Actions, "upload")
|
||||
|
||||
// No meta object may have been created for this repo.
|
||||
meta, err = git_model.GetLFSMetaObjectByOid(t.Context(), repo.ID, p.Oid)
|
||||
assert.NoError(t, err)
|
||||
assert.NotNil(t, meta)
|
||||
assert.Nil(t, meta)
|
||||
assert.Equal(t, git_model.ErrLFSObjectNotExist, err)
|
||||
|
||||
// Cleanup
|
||||
err = contentStore.Delete(p.RelativePath())
|
||||
|
||||
Reference in New Issue
Block a user