tree a4663631c826b67e4dd7463a0a9fb278a044aac9
parent fc8e99f041395f762093d21511c06800fc4029f6
author Nico Sallembien <nsallembien@google.com> 1272998952 -0700
committer Nico Sallembien <nsallembien@google.com> 1276015142 -0700

Simplify reference level access control.

The initial implementation of reference level access control only
supports a corner case, that of "locking down" access for a specific
branch.

Upon further discussion, we've decided that this is not the more
general need. Most Gerrit configurations prefer to have a more "open"
access model, where access rights on a reference specified with a
wildcard, such as "refs/heads/*" aren't overridden by a more specific
access right. So this change makes the default behavior to evaluate
all rights, including the wild card ones.

However, in order to accomodate the corner case we were supporting
before, this change also introduces a new way to specify exclusive
reference level access rights. All access rights that start with the
'-' prefix are considered exclusive, and will prevent all wild card
rights from being considered.

Change-Id: I629f5439967b2141e46098614fadb25ff28e5f45
