[Kde-scm-interest] Permissions on gitorious.org

Eike Hein hein at kde.org
Tue May 4 11:41:11 CEST 2010


On 05/04/2010 11:23 AM, Andreas Pakulat wrote:
> But I do have to wonder wether I'm the only one who thinks this is a bug in
> gitorious?

Kind of, yeah. As far as I can tell it's possible to lock yourself
and everyone out of being able to edit a repository's settings and
collaborator list by removing the "admin" flag from all collabora-
tors (your own last). At least if the project owning the repository
is owned by a team. Even admins of the team owning the project and
the repository cannot edit a repos without the admin flag. At that
point you need to ask the support ...

A feature we've also requested from Gitorious is to split the
"admin" flag into two distinct flags, one for editing the repo
settings (like force push, needed for tags and branches) and one
for editing the collaborator list, so we can make the latter ex-
clusive to kde-sysadmin and prevent someone who has gone crazy
from cutting off kde-*'s access totally and thus DoS'ing develop-
ment. Project admins would still be able to add reviewers by way
of admining their -reviewers team.

(Changes to the SVN ACLs also require a sysadmin request right now,
so it's not much different.)


Thank you for taking care of the KDevelop repo setup, I had a look
just now and everything looks just as it should :).


PS.: I locked myself out during the Konvi setup phase, too, and
we two are not the only ones ;-).


> Andreas

-- 
Best regards,
Eike Hein


More information about the Kde-scm-interest mailing list