Live QA: every call to /v1/devices/revoke returned 429 retry_after=3600.
The rule was written (0, 3600) with a comment saying 'never throttle someone
out of signing a lost laptop out' -- but in this limiter a limit of 0
DISABLES the endpoint outright. The comment said unlimited; the code said
never. Set to 600/hour instead.
Every unit test passed while the endpoint was 100% dead over HTTP, because
they called svc.revoke_device() directly and never went through the handler.
Added 4 tests that speak HTTP, including one that fails if ANY route in
DEFAULT_RATE_RULES is configured to 0.
176 tests (was 172).
Answers three questions that had no answer: which computers are connected,
how do I cut one off, and what is recorded.
- state.json gains a device registry hanging off the identity that owns it,
so 'which computers can reach my files' cannot drift from the identity map.
Clients older than v1.2 send no device_id and fall back to the token name,
so they still register.
- POST /v1/devices lists them; POST /v1/devices/revoke deletes that device's
forge token via admin basic auth + Sudo (verified 204 on 1.27.2, after
which the token is 401 immediately). Revocation is deliberately NOT rate
limited -- nobody should be throttled out of signing out a lost laptop.
- The device id is now part of the token NAME. Revocation deletes by name,
so two machines called 'macbook' linked in the same second would otherwise
collide and signing one out would kill the other.
- A failed forge deletion is not recorded as revoked: a registry claiming
'revoked' while the token still works is worse than an honest error.
- Append-only JSONL audit log (0600, rotates at 64MB), separate from
state.json because state is rewritten atomically on every change and an
audit trail the audited thing can rewrite is not one. A failed audit write
is logged loudly and never breaks the request.
- Authorisation everywhere: the forge decides who a token belongs to
(GET /api/v1/user). No login is ever read from the request body.
- Client: devices / logout / activity.
The audit log records granthi-link events only -- git pushes and pulls never
pass through this service. /v1/audit returns that caveat in its own response
rather than letting the log read as file activity.
172 tests (was 153).
Review found the read path scoped to the CURRENT device's uuid, which breaks
the exact case snapshot mode exists for: when the laptop dies, the
replacement machine has a new id, so snapshots printed 'no restore points
yet' while the backups sat on the forge, and restore errored. Reproduced,
then fixed by unscoping the READ only. Writing stays device-scoped (two
machines must not overwrite each other) and pruning stays device-scoped
(machine A must not apply its clock to machine B's refs); the docstring now
says why the three differ.
Also from the same review:
- mirror mode printed a %cI timestamp that restore could not accept, so
copying the first column looped the user back to snapshots. It now matches
the log, and refuses an ambiguous timestamp (two commits in one second)
with the candidate ids instead of guessing.
- the size guard advised 'add a .gitignore' while measuring with a plain
walk that ignored one. It now measures what git would sync, through a
throwaway git dir outside the folder so a refused add leaves no .git
behind.
- get --all caught only SystemExit, so a RuntimeError from any git call
abandoned the remaining repos.
- get --all mapped alice/notes and bob/notes to one path and reported the
second as 'already present'. Clashes now clone to <owner>-<name> and say so.
- the prune clock was in-memory, so watch --once under launchd pruned every
run. Persisted in config.
153 tests. Live-verified on the beta forge: machine A backed up uncommitted
work and was deleted; machine B, different device id, cloned the repo, listed
A's snapshot and restored both files.
Live QA against the beta forge failed its first push with 'Failed to
authenticate user' while the config held a valid token. Cause: credential.helper
is a list accumulated across system/global/repo config, and this machine has
osxkeychain (Xcode gitconfig) plus store (~/.gitconfig). A stale entry for the
forge host answered before our helper.
The same list is a token leak in the other direction: git calls approve on
every helper after a successful auth, so 'store' writes the forge token into
~/.git-credentials in plaintext -- undoing the 0600 config and the
no-token-in-URL rule. Confirmed accidentally during QA when a verification
clone with a URL-embedded token re-created exactly that entry.
Fix: set an empty credential.helper first (git reads that as 'forget the
inherited list'), then add ours -- in install_credential_helper and in the
git clone inside get.
2 regression tests, one of which drives 'git credential fill' against a
poisoned outer helper. 143 tests.
Two modes per linked folder. 'mirror' keeps today's behaviour for a plain
folder that add turned into a repo. 'snapshot' is new and is for a folder
that already had a git history: nothing is ever committed on the user's
behalf, and instead each pass builds a commit object from the working tree
via a scratch index + commit-tree and pushes it to
refs/granthi-backup/<device>/<ts>. HEAD, the index and every file stay
exactly as the user left them, so uncommitted, unmerged, half-finished work
leaves the machine with a timestamp to restore from.
Verified on the beta forge (Gitea 1.27.2) that a custom ref namespace is
accepted, readable via ls-remote, and absent from the branch list.
Also: retention (all for 24h, hourly for 7d, daily beyond; unparseable
timestamps kept), snapshots/restore commands, restore never writing over the
working tree, get --all bounded by what the forge grants, list <pattern>,
.gitignore seeding, an add size guard, and a persisted device_id.
141 tests (was 108).