Skip to content

api(encrypted): encrypted-blob and withheld-paths routes skip the quarantine gate #499

Description

@PierrunoYT

authorize_repo_read (crates/gitlawb-node/src/api/mod.rs:54-56) drops a quarantined repo before the visibility gate, so a quarantined mirror is hidden from every reader as if it did not exist. The three encrypted-blob handlers (api/encrypted.rs:21-31, 48-58, 84-93) and withheld_paths (api/visibility.rs:213-229) hand-roll the gate with get_repo + visibility_check and never call is_repo_quarantined.

Impact: a quarantined mirror's OID/CID index, and the full ciphertext of every withheld blob via GET .../encrypted-blob/{oid}, are still served, while clone, /ipfs/{cid} and every authorize_repo_read route return 404.

Repro: GET /api/v1/repos/{owner}/{repo}/encrypted-blobs against a quarantined mirror returns 200 with data.

Fix: route these handlers through authorize_repo_read, or add the quarantine check to the hand-rolled gate. Per AGENTS.md, add deny-path tests proving the quarantined repo now 404s on each.

Found in the Oct 2 2026 audit (A2) at bfc44f9.

Activity

  1. added
    kind:bugDefect fix — wrong or unsafe behavior
    sev:highMajor break or real security/trust risk, no easy workaround
    subsystem:apiNode REST API request/response surface
    subsystem:encryptionEncrypted subtrees, recipient blinding, key zeroization
    subsystem:visibilityPath-scoped visibility and content withholding
    crate:nodegitlawb-node — the serving node and REST API
    kind:securityVulnerability fix or hardening
    and removed
    kind:bugDefect fix — wrong or unsafe behavior
    on Oct 2, 2026
  2. beardthelion commented on Oct 2, 2026

    @beardthelion
    Collaborator

    This defect is already fixed in open PR #276, which routes the encrypted-blob handlers and withheld_paths through authorize_repo_read and covers the deny path with a test. Linking so this issue tracks it through merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:nodegitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surfacesubsystem:encryptionEncrypted subtrees, recipient blinding, key zeroizationsubsystem:visibilityPath-scoped visibility and content withholding

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions