CreateRefControl: Pass CurrentUser to Reachable

In ReceiveCommits context CurrentUser can be anonymous.
When CreateRefControl calls Reachable, Reachable uses the
PermissionBackend to filter refs visible to the CurrentUser.
This causes PermissionBackend to evaluate the pushing user
as anonymous even if they are authenticated.

When pushing annotated tags over HTTP with only permission CREATE_TAG
and the ref that the tag is reachable isn't visible to anonymous users,
Reachable will conclude that the tag isn't reachable from anywhere.
This in turn makes CreateRefControl conclude that the user isn't
allowed to push the tag and throw an AuthException:
"update for creating new commit object not permitted"

This did not affect pushes over SSH since a RequestContext is created
(by SshScope) before ReceiveCommits is called so CurrentUser was
available.

By passing the authenticated user to Reachable and use it to filter
the refs, we can assure that authenticated users are allowed to
push annotated tags when they have permission to create them.

Rewritten tests for pushing tags:
* Test with both SSH and HTTP.
* Remove READ for anonymous users.
  This effectively also removes all other permissions for Anonymous
  users since all permissions are dependent on READ.

Bug: Issue 8952
Change-Id: Iaa3e3620ca46c9c5a0e43f9b948f9d057ca861bf
10 files changed
tree: b0cba391c2274bfd9a93b1533a140ac44f56862e
  1. .settings/
  2. antlr3/
  3. contrib/
  4. Documentation/
  5. gerrit-gwtdebug/
  6. gerrit-gwtui/
  7. gerrit-gwtui-common/
  8. gerrit-plugin-gwtui/
  9. java/
  10. javatests/
  11. lib/
  12. plugins/
  13. polygerrit-ui/
  14. prolog/
  15. prologtests/
  16. proto/
  17. resources/
  18. tools/
  19. webapp/
  20. .bazelignore
  21. .bazelproject
  22. .bazelrc
  23. .bazelversion
  24. .editorconfig
  25. .git-blame-ignore-revs
  26. .gitignore
  27. .gitmodules
  28. .gitreview
  29. .mailmap
  30. .pydevproject
  31. BUILD
  32. COPYING
  33. INSTALL
  34. Jenkinsfile
  35. package.json
  36. README.md
  37. SUBMITTING_PATCHES
  38. version.bzl
  39. WORKSPACE
README.md

Gerrit Code Review

Gerrit is a code review and project management tool for Git based projects.

Build Status

Objective

Gerrit makes reviews easier by showing changes in a side-by-side display, and allowing inline comments to be added by any reviewer.

Gerrit simplifies Git based project maintainership by permitting any authorized user to submit changes to the master Git repository, rather than requiring all approved changes to be merged in by hand by the project maintainer.

Documentation

For information about how to install and use Gerrit, refer to the documentation.

Source

Our canonical Git repository is located on googlesource.com. There is a mirror of the repository on Github.

Reporting bugs

Please report bugs on the issue tracker.

Contribute

Gerrit is the work of hundreds of contributors. We appreciate your help!

Please read the contribution guidelines.

Note that we do not accept Pull Requests via the Github mirror.

Getting in contact

The Developer Mailing list is repo-discuss on Google Groups.

License

Gerrit is provided under the Apache License 2.0.

Build

Install Bazel and run the following:

    git clone --recurse-submodules https://gerrit.googlesource.com/gerrit
    cd gerrit && bazel build release

Install binary packages (Deb/Rpm)

The instruction how to configure GerritForge/BinTray repositories is here

On Debian/Ubuntu run:

    apt-get update & apt-get install gerrit=<version>-<release>

NOTE: release is a counter that starts with 1 and indicates the number of packages that have been released with the same version of the software.

On CentOS/RedHat run:

    yum clean all && yum install gerrit-<version>[-<release>]

On Fedora run:

    dnf clean all && dnf install gerrit-<version>[-<release>]

Use pre-built Gerrit images on Docker

Docker images of Gerrit are available on DockerHub

To run a CentOS 7 based Gerrit image:

    docker run -p 8080:8080 gerritforge/gerrit-centos7[:version]

To run a Ubuntu 15.04 based Gerrit image:

    docker run -p 8080:8080 gerritforge/gerrit-ubuntu15.04[:version]

NOTE: release is optional. Last released package of the version is installed if the release number is omitted.