Conversation
Git clone tokens were minted as ordinary access JWTs and verified only
by checking that the token subject owned the requested app. This let a
token minted for one private app clone any other private app owned by
the same user, since the app-specific sessionId claim was never
checked at verification time.
Replace the token shape with a dedicated, purpose-scoped credential
that binds the owner and the exact repository backend (Think app Space
vs. agent-managed git). Both git smart-HTTP endpoints now require an
exact target match in addition to current ownership, and the token can
no longer be parsed as a normal API access token.
- worker/utils/gitCloneToken.ts: git-only JWT claims/signer/verifier
bound to { userId, target } where target discriminates Space vs.
agent repositories
- worker/agents/index.ts: shared resolver mapping an app id to its
repository target, reused by both minting and verification
- worker/api/controllers/appView/controller.ts: mint tokens scoped to
the resolved target instead of a generic access token
- worker/api/handlers/git-protocol.ts: verify target + ownership
before serving repository data; treat malformed Basic auth as 401
instead of a 500
- add regression coverage for cross-app reuse, cross-backend
confusion, cross-owner tokens, generic-token rejection, and
malformed auth headers
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Files changed
Test plan