Nirav Patel and Claude Fable 5
14ccbd59f0
test+docs: startup-refusal exit code, real-body 413, pre-1.1.0 migration note
...
- main() exits 2 on permissive config (not just the predicate)
- 413 proven with an actual over-limit wire body, not header-only
- README: machine-user accounts need a seeded state.json mapping; only
granthi-sync-e2e required it in beta
Co-Authored-By: Claude Fable 5 <[email protected] >
2026-08-19 09:25:13 -04:00
Nirav Patel and Claude Fable 5
c674db4746
security: harden granthi-link + client against 7 codex findings
...
1. CRITICAL account-takeover by login collision: persist zitadel_sub ->
gitea_login identity map (state.json, 0600, atomic); mapping wins,
deleted logins re-created only if service-created, existing unmapped
logins bind only on verified email match, else 409; token never
minted before binding passes
2. test_mode now gated behind GRANTHI_LINK_ALLOW_TEST_MODE=1 env
3. refuse startup unless config.json is 0600/0400 and owned by service
4. client config created O_CREAT 0600 (no write-then-chmod window)
5. credential-helper command paths shlex-quoted
6. POST bodies capped at 64KB (413); missing/invalid Content-Length rejected
7. Gitea 409 on user create handled idempotently (re-fetch + verify email)
Co-Authored-By: Claude Fable 5 <[email protected] >
2026-08-19 09:17:26 -04:00