fix: enforce public-only token scope and harden push options / locale parsing (#38323)

- **Locale DoS:** the `Locale` middleware passed the raw
`Accept-Language` header to `ParseAcceptLanguage`, whose guard only
counts `-` while the scanner aliases `_` to `-` — a large `_`-separated
header on an unauthenticated request burned CPU. The header is now
length-bounded before parsing.
- **Public-only token scope:** `GET /teams/{id}/repos`,
`.../repos/{org}/{repo}`, `/teams/{id}/activities/feeds`, and
`/users/{username}/orgs/{org}/permissions` still returned private
repo/activity/permission data to a public-only token. They now filter
via `TokenCanAccessRepo` / `ApplyPublicOnly` and reject non-public org
permissions.
- **Push-option visibility:** `repo.private` / `repo.template` push
options were applied to any existing repo, letting an owner/admin
silently flip visibility bypassing audit, webhooks, and notifications.
They are now honored only on push-to-create.
This commit is contained in:
bircni
2026-07-10 18:39:01 +02:00
committed by GitHub
parent c5c991b1a4
commit f452c369ac
8 changed files with 207 additions and 17 deletions
+38
View File
@@ -11,6 +11,7 @@ import (
auth_model "gitea.dev/models/auth"
"gitea.dev/models/db"
git_model "gitea.dev/models/git"
repo_model "gitea.dev/models/repo"
"gitea.dev/models/unittest"
user_model "gitea.dev/models/user"
"gitea.dev/modules/git"
@@ -140,6 +141,43 @@ func testGitPush(t *testing.T, u *url.URL) {
})
}
func TestGitPushVisibilityOption(t *testing.T) {
onGiteaRun(t, func(t *testing.T, u *url.URL) {
user := unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: 2})
repo, err := repo_service.CreateRepository(t.Context(), user, user, repo_service.CreateRepoOptions{
Name: "repo-visibility-option",
AutoInit: false,
DefaultBranch: "master",
IsPrivate: false,
})
require.NoError(t, err)
require.NotEmpty(t, repo)
gitPath := t.TempDir()
doGitInitTestRepository(gitPath)(t)
oldPath, oldUser := u.Path, u.User
defer func() { u.Path, u.User = oldPath, oldUser }()
u.Path = repo.FullName() + ".git"
u.User = url.UserPassword(user.LowerName, userPassword)
doGitAddRemote(gitPath, "origin", u)(t)
// The first push into an empty repository is a "push-to-create", so the
// repo.private push option is honored to set the initial visibility.
doGitPushTestRepository(gitPath, "origin", "master", "-o", "repo.private=true")(t)
repo = unittest.AssertExistsAndLoadBean(t, &repo_model.Repository{ID: repo.ID})
assert.True(t, repo.IsPrivate, "repo.private option should apply on push-to-create")
// The repository is now populated; a later push must NOT silently flip
// visibility, otherwise a repo admin could change it bypassing the audit
// trail, webhooks, and notifications a proper settings change would fire.
doGitCreateBranch(gitPath, "branch2")(t)
doGitPushTestRepository(gitPath, "origin", "branch2", "-o", "repo.private=false")(t)
repo = unittest.AssertExistsAndLoadBean(t, &repo_model.Repository{ID: repo.ID})
assert.True(t, repo.IsPrivate, "repo.private option must be ignored on an existing repository")
})
}
func runTestGitPush(t *testing.T, u *url.URL, gitOperation func(t *testing.T, gitPath string) (pushed, deleted []string)) {
user := unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: 2})
repo, err := repo_service.CreateRepository(t.Context(), user, user, repo_service.CreateRepoOptions{