radicle-heartwood-lfs/radicle-cli/examples
cloudhead 989edacd56
Include new `rad/root` in signed refs
We ensure that a `rad/root` ref is included in the signed refs file
under `rad/sigrefs` for all remotes. This prevents a certain kind of
"grafting" attack where signed refs can be copied between repositories,
by having the peer sign over the identity root together with the data refs.

When verifying signed refs, we ensure that the ref is present and points
to an identity branch root that matches the repository identity containing
the signed refs.

Alternatives: lots of alternatives were considered, but this one doesn't
introduce any changes to the signing. The `rad/id/root` name was
considered but is invalid due to `rad/id`.
2024-10-21 16:32:49 +02:00
..
framework cli-test: Update framework with new features 2023-08-04 12:23:49 +02:00
git radicle: add tags fetch refspec 2024-10-21 14:30:37 +02:00
workflow cli: announce on issue edit and comment 2024-08-20 16:32:02 +02:00
rad-auth-errors.md radicle: Fix config loading with bad alias 2024-03-21 14:44:04 +01:00
rad-auth.md radicle: Fix config loading with bad alias 2024-03-21 14:44:04 +01:00
rad-block.md cli: add `rad unblock` command 2024-08-06 14:12:44 +02:00
rad-checkout-repo-config-linux.md radicle: add tags fetch refspec 2024-10-21 14:30:37 +02:00
rad-checkout-repo-config-macos.md radicle: add tags fetch refspec 2024-10-21 14:30:37 +02:00
rad-checkout.md cli: Add canonical remote to `init` and `checkout` 2023-04-24 15:42:00 +02:00
rad-clean.md Include new `rad/root` in signed refs 2024-10-21 16:32:49 +02:00
rad-clone-all.md Include new `rad/root` in signed refs 2024-10-21 16:32:49 +02:00
rad-clone-connect.md fetch: update gix-pack and gix-odb 2024-08-09 12:41:01 +02:00
rad-clone-directory.md Use "repository" consistently over "project" 2024-01-22 21:18:54 +01:00
rad-clone-partial-fail.md fetch: update gix-pack and gix-odb 2024-08-09 12:41:01 +02:00
rad-clone-unknown.md node: Rename node `tracking` module 2023-12-06 10:00:45 +01:00
rad-clone.md cli: Rename `rad ls --seeds` flag 2024-03-11 10:46:09 +01:00
rad-cob-log.md node: Update inventory when unseeding 2024-06-12 15:36:34 +02:00
rad-cob-show.md Add `id` to `Revision`, forbid duplicate reviews 2024-07-24 16:46:24 +02:00
rad-config.md node: Simplify configuration 2024-06-04 14:08:15 +02:00
rad-diff.md cli: Improve pretty diff printing 2024-07-12 16:36:04 +02:00
rad-fetch.md cli: From "tracking" to "seeding" and "following" 2023-12-06 09:56:57 +01:00
rad-fork.md Include new `rad/root` in signed refs 2024-10-21 16:32:49 +02:00
rad-id-collaboration.md radicle: fault tolerant thresholds 2024-04-03 14:30:05 +02:00
rad-id-conflict.md radicle: UserInfo for Repository::create 2023-11-09 16:43:34 +01:00
rad-id-multi-delegate.md Include new `rad/root` in signed refs 2024-10-21 16:32:49 +02:00
rad-id-private.md cli: idempotent `rad id update` 2024-06-21 13:01:59 +02:00
rad-id-threshold-soft-fork.md Include new `rad/root` in signed refs 2024-10-21 16:32:49 +02:00
rad-id-threshold.md Include new `rad/root` in signed refs 2024-10-21 16:32:49 +02:00
rad-id-unknown-field.md cli: Add test for unknown field in identity doc 2024-05-07 10:21:07 +02:00
rad-id-update-delete-field.md cli: idempotent `rad id update` 2024-06-21 13:01:59 +02:00
rad-id.md cli: idempotent `rad id update` 2024-06-21 13:01:59 +02:00
rad-inbox.md cli: fix rad inbox clear output 2024-04-09 16:09:44 +02:00
rad-init-existing.md cli: Add way to init from existing repositories 2024-07-29 11:49:19 +02:00
rad-init-no-git.md cli: Improve `rad init` wording 2024-03-11 13:08:03 +01:00
rad-init-no-seed.md cli: Correctly update inventory with seed commands 2024-06-12 15:36:34 +02:00
rad-init-private-clone-seed.md cli: Add `--from` and other options to `rad seed` 2024-06-25 12:01:52 +02:00
rad-init-private-clone.md cli: Simplify private repo fetching 2024-05-16 15:46:24 +02:00
rad-init-private-no-seed.md cli: Clarify doc test example 2024-06-12 15:36:34 +02:00
rad-init-private-seed.md cli: Simplify private repo fetching 2024-05-16 15:46:24 +02:00
rad-init-private.md cli: Correctly update inventory with seed commands 2024-06-12 15:36:34 +02:00
rad-init-sync-not-connected.md cli: Show full path in `rad init` 2024-02-26 12:40:17 +01:00
rad-init-sync-preferred.md cli: watch for upload-pack events in `rad init` 2024-05-15 10:07:56 +01:00
rad-init-sync-timeout.md cli: Show full path in `rad init` 2024-02-26 12:40:17 +01:00
rad-init-sync.md cli: Show full path in `rad init` 2024-02-26 12:40:17 +01:00
rad-init-with-existing-remote.md test: Fix backwards incompatibility with git 2.34 2024-06-12 12:13:10 +02:00
rad-init.md cli: Correctly update inventory with seed commands 2024-06-12 15:36:34 +02:00
rad-inspect-noauth.md cli: Improve messaging when config doesn't load 2023-12-13 12:30:11 +01:00
rad-inspect.md Include new `rad/root` in signed refs 2024-10-21 16:32:49 +02:00
rad-issue.md node: Update inventory when unseeding 2024-06-12 15:36:34 +02:00
rad-merge-after-update.md cob: Properly authorize root actions 2024-02-23 12:31:13 +01:00
rad-merge-no-ff.md cob: Properly authorize root actions 2024-02-23 12:31:13 +01:00
rad-merge-via-push.md Include new `rad/root` in signed refs 2024-10-21 16:32:49 +02:00
rad-node.md cli: Correctly update inventory with seed commands 2024-06-12 15:36:34 +02:00
rad-patch-ahead-behind.md node: Update inventory when unseeding 2024-06-12 15:36:34 +02:00
rad-patch-change-base.md node: Update inventory when unseeding 2024-06-12 15:36:34 +02:00
rad-patch-checkout-force.md cli: show revision on rad patch checkout 2024-03-11 11:56:11 +01:00
rad-patch-checkout-revision.md node: Update inventory when unseeding 2024-06-12 15:36:34 +02:00
rad-patch-checkout.md cli: show revision on rad patch checkout 2024-03-11 11:56:11 +01:00
rad-patch-delete.md node: handle removal of cob from cache 2024-04-09 16:06:51 +02:00
rad-patch-detached-head.md remote-helper: allow patch creation from detached HEAD 2024-07-23 17:13:30 +02:00
rad-patch-diff.md cob: Properly authorize root actions 2024-02-23 12:31:13 +01:00
rad-patch-draft.md node: Update inventory when unseeding 2024-06-12 15:36:34 +02:00
rad-patch-edit.md node: Update inventory when unseeding 2024-06-12 15:36:34 +02:00
rad-patch-fetch-1.md cli: use `git` for anonymous fetch 2024-01-02 15:04:49 +01:00
rad-patch-fetch-2.md cob: Properly authorize root actions 2024-02-23 12:31:13 +01:00
rad-patch-merge-draft.md cob: Properly authorize root actions 2024-02-23 12:31:13 +01:00
rad-patch-open-explore.md cob: Properly authorize root actions 2024-02-23 12:31:13 +01:00
rad-patch-pull-update.md cli: show revision on rad patch checkout 2024-03-11 11:56:11 +01:00
rad-patch-revert-merge.md helper: Revert patches correctly 2024-08-23 15:59:59 +02:00
rad-patch-update.md node: Update inventory when unseeding 2024-06-12 15:36:34 +02:00
rad-patch-via-push.md node: Update inventory when unseeding 2024-06-12 15:36:34 +02:00
rad-patch.md node: Update inventory when unseeding 2024-06-12 15:36:34 +02:00
rad-publish.md cli: Correctly update inventory with seed commands 2024-06-12 15:36:34 +02:00
rad-push-and-pull-patches.md cli: show revision on rad patch checkout 2024-03-11 11:56:11 +01:00
rad-remote.md cli: Improve `rad remote add` 2024-01-08 17:28:01 +01:00
rad-review-by-hunk.md cli: Write comments into draft patch review 2024-07-24 16:46:24 +02:00
rad-seed-and-follow.md cli: Fix some tests 2024-03-09 14:01:30 +01:00
rad-self.md cli: Move node addresses command 2024-02-26 14:23:13 +01:00
rad-sync-without-node.md cli: From "tracking" to "seeding" and "following" 2023-12-06 09:56:57 +01:00
rad-sync.md Include new `rad/root` in signed refs 2024-10-21 16:32:49 +02:00
rad-unseed.md cli: Correctly update inventory with seed commands 2024-06-12 15:36:34 +02:00
rad-watch.md cli: Add `watch` command 2023-12-11 12:04:26 +01:00