Fix #345: public/private visibility #353
No reviewers
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub!353
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/issue-345"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes #345: visibility becomes the read authority for repo surfaces; listings filter by caller role.
Spec amendment (stated explicitly, 06 §8.3 / 07 §13 / Decisions)
anonymous_readno longer gates repo-scoped reads. Visibility (access.json, public-by-default, missing/empty/invalid resolves public) decides: public ⇒ readable without authentication (even withanonymous_read=false); private ⇒ 401 anonymous / 403 authenticated-without-read. The flag keeps only its non-repo meaning: owners/profile/org listings,/exploreshell + text twin, setup.json,/+/{owner}shells, identity user/org surfaces. Nil read gate → legacy flag-only behavior everywhere. Built ON the #344 merge (ceb7331): login page/validation untouched — private shells keep the 401 + #344 login page / 307 hop for browsers.Permission matrix (surface × visibility × principal)
Repo read surfaces = JSON API lanes, smart-HTTP upload-pack, LFS reads, bundle lists, SSH fetch, repo SPA shells. Writes/admin ops unchanged everywhere (authenticated + flags/bindings; anonymous never).
What changed
CheckReaddrops theanonymous_readconjunction (anon+public allows); newRepoVisibility(LRU-backed, missing→public, nil-svc→unknown).open()consultCheckReadBEFORE the flag for repo AuthRead;Visible{Repos,Owners,ReposByOwner}filters (admins/writers +0 probes); catalog rollup folds after filtering;summaryBody+RepoSizeRowcarryvisibilitywith~vETag suffix; newEnv.RepoVisibilityhook.gateRepoRead(smart ×3, LFS);SSHUploadPacktakes the principal + read-gates first;repoPageGatedshells;/exploretext twin filtered.apiEnv.RepoVisibilitywired (law 8, MirrorSummary shape).lib/visibility.js), General-tab control (admin PUT preserving bindings), create flow already sent visibility; fork/import default public documented.Cost (law 6)
Listing filters = one conditional
access.jsonGET per candidate repo (LRU version-hits carry no body); hot-path budgets untouched (push/refs/checkpoint never call here). Summary + rows reuse the trip the read gate already paid.make covergate holds (api 95.3%, identity 97.2%, server 98.5%, sshd 96.5%).Tests
Table-driven matrix cells:
internal/api/visibility345_test.go(dispatch, ETag flip, listings, rollup filter, helpers),internal/identity/gate_test.go(flag-off matrix, RepoVisibility incl. corrupt/missing),internal/server/visibility345_test.go(gates, shell incl. #344 page, SSH ordering),web/test/unit/visibility.test.js.go vet ./...clean;-raceclean;internal/e2egreen; dependents (repoimport/pulls/issues/review/checks/social/notify/releases/tags/sizecatalog, cmd) green. No new deps.Known environment gaps (pre-existing, fail on pristine scratch too)
TestUIAssetConcepts+TestSetupUIAndAssets-class shell tests need a fullmake webbuild (scratch has only a copied dist; no pnpm here)./; left untouched).