Harden secret-file creation, token comparison and git refname args
Works off the security audit in docs/prs/2026-07-08-PR#000: TODO 1, 8, 9 and 10, the four items that need no design decision. New `SecretFiles` creates files holding secrets with mode 0600 and their directories with 0700 *at creation*, as a file attribute, instead of writing at the umask default and chmod-ing afterwards — that left a window in which the Gitea token was world-readable, which matters on a multi-tenant host. It is used by `init` for .git/gittally/.gittally.yml and by `ControlTokenService` for the control token; the shell setup script now writes its YAML in a `umask 077` subshell for the same reason. `ControlTokenService.matches` hashes both sides with SHA-256 before `MessageDigest.isEqual`, so the comparison always runs over two 32-byte buffers and cannot return early on a length mismatch. `GitService.checkout` and `fetchBranch` pass `--` before the refname, so a branch named like an option cannot be read as one. `resetHardToOrigin` keeps its plain form: `git reset --hard -- <commit>` is rejected outright and its argument is already `origin/`-prefixed. Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -244,13 +244,19 @@ echo "== writing $project_yml (public host: $hostname, source: $config_source)"
|
||||
|
||||
echo "== writing $machine_yml (secrets, mode 600)"
|
||||
mkdir -p "$(dirname "$machine_yml")"
|
||||
{
|
||||
echo "# Machine-specific overrides and secrets. Keys here win over .gittally.yml."
|
||||
echo "git:"
|
||||
echo " account: $(yaml_quote "$git_account")"
|
||||
echo " token: $(yaml_quote "$git_token")"
|
||||
} >"$machine_yml"
|
||||
chmod 600 "$machine_yml"
|
||||
# the umask in the subshell makes the file mode 600 at creation, so the token is
|
||||
# never world-readable — not even between the redirect and a follow-up chmod;
|
||||
# an existing file is removed first, because the redirect would keep its mode
|
||||
rm -f "$machine_yml"
|
||||
(
|
||||
umask 077
|
||||
{
|
||||
echo "# Machine-specific overrides and secrets. Keys here win over .gittally.yml."
|
||||
echo "git:"
|
||||
echo " account: $(yaml_quote "$git_account")"
|
||||
echo " token: $(yaml_quote "$git_token")"
|
||||
} >"$machine_yml"
|
||||
)
|
||||
|
||||
echo "== converted project config:"
|
||||
sed 's/^/ /' "$project_yml"
|
||||
|
||||
Reference in New Issue
Block a user