Skip to content

api(encrypted): encrypted-blob and withheld-paths routes skip the quarantine gate #499

Description

@PierrunoYT

authorize_repo_read (crates/gitlawb-node/src/api/mod.rs:54-56) drops a quarantined repo before the visibility gate, so a quarantined mirror is hidden from every reader as if it did not exist. The three encrypted-blob handlers (api/encrypted.rs:21-31, 48-58, 84-93) and withheld_paths (api/visibility.rs:213-229) hand-roll the gate with get_repo + visibility_check and never call is_repo_quarantined.

Impact: a quarantined mirror's OID/CID index, and the full ciphertext of every withheld blob via GET .../encrypted-blob/{oid}, are still served, while clone, /ipfs/{cid} and every authorize_repo_read route return 404.

Repro: GET /api/v1/repos/{owner}/{repo}/encrypted-blobs against a quarantined mirror returns 200 with data.

Fix: route these handlers through authorize_repo_read, or add the quarantine check to the hand-rolled gate. Per AGENTS.md, add deny-path tests proving the quarantined repo now 404s on each.

Found in the Oct 2 2026 audit (A2) at bfc44f9.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:nodegitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surfacesubsystem:encryptionEncrypted subtrees, recipient blinding, key zeroizationsubsystem:visibilityPath-scoped visibility and content withholding

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions