Split up signed references into its read and write components. On the write side: - Preserve the old behavior of writing references to the blob `/refs` and sign over the blob. - Ensure `refs/rad/root` is contained in the `/refs` blob. - Ensure `refs/rad/sigrefs` is *not* contained in the `/refs` blob. - Introduce a new (internal) reference `refs/rad/sigrefs-parent` so that no two `/refs` blob are equal, even if they contain the same set of (non-internal) refs. On the read side: - Preserve the verification of the signature in `/signature` and the reference `refs/rad/root` (if present). - Fail verification of `refs/rad/root` is not present. - Protect against replay attacks by walking the history of the head of `refs/rad/sigrefs`, skipping interpretation of `/refs` blobs in case they are identical to a previous `/refs` blob. This is achieved by searching for repeated contents of the `/signature` blob. The reference `refs/rad/sigrefs-parent` is never read from or written to the Git repository in storage. The pre-existing implementation of signed references did not include a nonce, thus duplicate but legitimate sets of references could not be distinguished from maliciously replayed sets of references. The new implementation uses `radicle-git-metadata` which is moved from `dev-dependencies` to `dependencies`. |
||
|---|---|---|
| .. | ||
| src | ||
| CHANGELOG.md | ||
| Cargo.toml | ||