fix(git): restrict hook permissions (#39008)

Create delegate hook files and directories without group or other write
access, including correcting existing hook directories.

_Assisted-by: Codex:GPT-5_
This commit is contained in:
bircni
2026-08-21 09:52:23 +02:00
committed by GitHub
parent db24633e6d
commit a52e5f53c0
2 changed files with 42 additions and 4 deletions
+34
View File
@@ -0,0 +1,34 @@
// Copyright 2026 The Gitea Authors. All rights reserved.
// SPDX-License-Identifier: MIT
package git
import (
"os"
"path/filepath"
"testing"
"github.com/stretchr/testify/require"
)
func TestCreateDelegateHooksPermissions(t *testing.T) {
hookDir := t.TempDir()
existingHookDir := filepath.Join(hookDir, "post-receive.d")
require.NoError(t, os.MkdirAll(existingHookDir, 0o777))
require.NoError(t, os.Chmod(existingHookDir, 0o777))
require.NoError(t, createDelegateHooks(hookDir))
hookNames, _, _ := getHookTemplates()
for _, hookName := range hookNames {
for _, path := range []string{
filepath.Join(hookDir, hookName),
filepath.Join(hookDir, hookName+".d"),
filepath.Join(hookDir, hookName+".d", "gitea"),
} {
info, err := os.Stat(path)
require.NoError(t, err)
require.Equal(t, os.FileMode(0o755), info.Mode().Perm(), path)
}
}
}