keybase / keybase/keybase-issues

Read-only Git Repositories

Open
#3,303 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Hi,

I use Keybase's encrypted repositories to manage dotfile configurations.

I would like a way to provide read-only access to some repositories on a per-machine basis because presently it seems any machine can push to the repo, meaning that if my most insecure machine gets compromised then it compromises every machine that uses the same dotfiles, if I pull from origin before noticing some changes were not mine.

As much overhead as it would be to maintain it, I would also just settle for per-user permissions in team repositories. IMO that is broken right now, team permissions are a must and it seems any team member can push to master.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing how Keybase encrypted repositories currently authorize pulls and pushes, then compare the per-machine read-only and per-user team permission requirements in the issue. Done would mean a defined, implemented permission model that prevents unauthorized pushes while preserving permitted repository access.

Written by the indexing model from the issue text.

Assessment

Domain
authorization, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.