From e5aaa5db9b323f58d9eb8338532fd04fce885048 Mon Sep 17 00:00:00 2001 From: James Moger Date: Mon, 22 Oct 2012 16:22:37 -0400 Subject: [PATCH] Permission regexes are now case-insensitive --- docs/01_setup.mkd | 4 ++-- docs/04_releases.mkd | 4 ++-- src/com/gitblit/models/TeamModel.java | 5 +++-- src/com/gitblit/models/UserModel.java | 4 ++-- src/com/gitblit/utils/StringUtils.java | 13 +++++++++++++ tests/com/gitblit/tests/PermissionsTest.java | 2 +- 6 files changed, 23 insertions(+), 9 deletions(-) diff --git a/docs/01_setup.mkd b/docs/01_setup.mkd index b5c407ea..6d015a3e 100644 --- a/docs/01_setup.mkd +++ b/docs/01_setup.mkd @@ -264,9 +264,9 @@ These permission codes are combined with the repository path to create a user pe #### Discrete Permissions with Regex Matching (Gitblit v1.2.0+) -Gitblit also supports regex matching for repository permissions. The following permission grants push privileges to all repositories in the *mygroup* folder. +Gitblit also supports *case-insensitive* regex matching for repository permissions. The following permission grants push privileges to all repositories in the *mygroup* folder. - RW:mygroup/[A-Za-z0-9-~_\\./]+ + RW:mygroup/[a-z0-9-~_\\./]+ #### No-So-Discrete Permissions (Gitblit <= v1.1.0) diff --git a/docs/04_releases.mkd b/docs/04_releases.mkd index 1ac7de3a..ae3ba621 100644 --- a/docs/04_releases.mkd +++ b/docs/04_releases.mkd @@ -32,8 +32,8 @@ If you are updating your server, you must also update any Gitblit Manager and Fe - RWD (clone and push with ref creation, deletion) - RW+ (clone and push with ref creation, deletion, rewind) While not as sophisticated as Gitolite, this does give finer access controls. These permissions fit in cleanly with the existing users.conf and users.properties files. In Gitblit <= 1.1.0, all your existing user accounts have RW+ access. If you are upgrading to 1.2.0, the RW+ access is *preserved* and you will have to lower/adjust accordingly. -- Implemented regex repository permission matching (issue 36) -This allows you to specify a permission like `RW:mygroup/[A-Za-z0-9-~_\\./]+` to grant push privileges to all repositories within the *mygroup* project/folder. +- Implemented *case-insensitive* regex repository permission matching (issue 36) +This allows you to specify a permission like `RW:mygroup/[a-z0-9-~_\\./]+` to grant push privileges to all repositories within the *mygroup* project/folder. - Added DELETE, CREATE, and NON-FAST-FORWARD ref change logging - Added support for personal repositories. Personal repositories can be created by accounts with the *create* permission and are stored in *git.repositoriesFolder/~username*. Each user with personal repositories will have a user page, something like the GitHub profile page. Personal repositories have all the same features as common repositories, except personal repositories can be renamed by their owner. diff --git a/src/com/gitblit/models/TeamModel.java b/src/com/gitblit/models/TeamModel.java index 9ba2f669..6410eb45 100644 --- a/src/com/gitblit/models/TeamModel.java +++ b/src/com/gitblit/models/TeamModel.java @@ -29,6 +29,7 @@ import com.gitblit.Constants.AccessPermission; import com.gitblit.Constants.AccessRestrictionType; import com.gitblit.Constants.RegistrantType; import com.gitblit.Constants.Unused; +import com.gitblit.utils.StringUtils; /** * TeamModel is a serializable model class that represents a group of users and @@ -184,9 +185,9 @@ public class TeamModel implements Serializable, Comparable { permission = p; } } else { - // search for regex permission match + // search for case-insensitive regex permission match for (String key : permissions.keySet()) { - if (repository.name.matches(key)) { + if (StringUtils.matchesIgnoreCase(repository.name, key)) { AccessPermission p = permissions.get(key); if (p != null) { permission = p; diff --git a/src/com/gitblit/models/UserModel.java b/src/com/gitblit/models/UserModel.java index 97430bfe..6cc07789 100644 --- a/src/com/gitblit/models/UserModel.java +++ b/src/com/gitblit/models/UserModel.java @@ -227,9 +227,9 @@ public class UserModel implements Principal, Serializable, Comparable return p; } } else { - // search for regex permission match + // search for case-insensitive regex permission match for (String key : permissions.keySet()) { - if (repository.name.matches(key)) { + if (StringUtils.matchesIgnoreCase(repository.name, key)) { AccessPermission p = permissions.get(key); if (p != null) { permission = p; diff --git a/src/com/gitblit/utils/StringUtils.java b/src/com/gitblit/utils/StringUtils.java index d115f896..02cc49fd 100644 --- a/src/com/gitblit/utils/StringUtils.java +++ b/src/com/gitblit/utils/StringUtils.java @@ -692,4 +692,17 @@ public class StringUtils { } return path; } + + /** + * Variation of String.matches() which disregards case issues. + * + * @param regex + * @param input + * @return true if the pattern matches + */ + public static boolean matchesIgnoreCase(String input, String regex) { + Pattern p = Pattern.compile(regex, Pattern.CASE_INSENSITIVE); + Matcher m = p.matcher(input); + return m.matches(); + } } \ No newline at end of file diff --git a/tests/com/gitblit/tests/PermissionsTest.java b/tests/com/gitblit/tests/PermissionsTest.java index 2f47a489..c0e406d4 100644 --- a/tests/com/gitblit/tests/PermissionsTest.java +++ b/tests/com/gitblit/tests/PermissionsTest.java @@ -2399,7 +2399,7 @@ public class PermissionsTest extends Assert { repository.accessRestriction = AccessRestrictionType.VIEW; UserModel user = new UserModel("test"); - user.setRepositoryPermission("ubercool/[A-Za-z0-9-~_\\./]+", AccessPermission.CLONE); + user.setRepositoryPermission("ubercool/[A-Z0-9-~_\\./]+", AccessPermission.CLONE); assertTrue("user DOES NOT HAVE a repository permission!", user.hasRepositoryPermission(repository.name)); assertTrue("user CAN NOT view!", user.canView(repository)); -- 2.39.5