Repository navigation
Commit 06388ec
feat(gl): sanctioned iCaptcha client flow + secure git lifecycle (#138)
* feat(gl): sanctioned iCaptcha client flow + secure git lifecycle
Builds the client side of the iCaptcha gate so a legitimate agent passes the
challenge transparently, with no manual headers and no GITLAWB_ICAPTCHA_PROOF
env var. Server enforcement is unchanged.
New crate `icaptcha-client` (blocking, shared by gl + the git helper):
- deterministic solvers for the computational challenge types (arithmetic,
algebra, sequence) matching the iCaptcha generators; anagram/logic/LLM fall
back to a solver hook / interactive prompt.
- obtain_proof(): POST /v1/challenge (requesterId = caller DID), solve, POST
/v1/answer, handle escalation, return the signed proof. Optional bearer auth
via GITLAWB_ICAPTCHA_API_KEY.
gl (crates/gl):
- http.rs: unify post/put/delete through one signed sender that, on a 403
iCaptcha challenge (detected via x-icaptcha-url / x-icaptcha-level headers),
solves it and retries the same signed request with the x-icaptcha-proof
header (bounded retry absorbs the ~5 min proof TTL). Removes the env hack.
Emits an actionable hint on 401 not_an_agent (old-CLI / unregistered).
- repo.rs: `repo info` checks status and returns a real 404 instead of a stub
card with `?` fields; `repo info`/`clone` resolve the owner from the local
identity or an explicit owner/name — never the node's own DID.
- doctor.rs: warn on gl-vs-node version drift; add an iCaptcha reachability
check.
git-remote-gitlawb: same shared client — push stays signed (RFC 9421); on a 403
iCaptcha (safety net; push is signed-only, not gated) it solves and retries.
Clone/fetch unsigned; missing repo keeps its clear 404.
gitlawb-node: the 403 icaptcha_proof_required response now advertises the
service url + required level as JSON fields and x-icaptcha-url / x-icaptcha-level
headers (mirroring the human_detected pattern) so clients discover them instead
of scraping the message. The sub == authenticated-DID and expiry/level checks
are unchanged — enforcement is not weakened.
README: documents the full lifecycle (identity -> register -> repo create with
auto-iCaptcha -> push -> clone), the requesterId == DID rule, and proof TTL.
Tested: solver unit tests; full workspace green against Postgres (node still
rejects missing/expired/wrong-subject proofs).
* fix(icaptcha-client,gl): address PR #138 review feedback
Rebased onto main (resolving the git-remote-gitlawb/main.rs conflict from #119)
and addressed the review findings:
- [beardthelion P2 / jatmn P2 / CodeRabbit] Removed the dead iCaptcha retry loop
from the push path. git_receive_pack never calls verify_request (only
create/fork/register are iCaptcha-gated), so a push 403 never carries
x-icaptcha-* headers and the loop could never solve. Taking main's push path
(via #119) deletes it, which also resolves the pack-clone (retries no longer
copy the whole pack) and the interactive-prompt-over-git-stream threads, and
restores the sanitized info/refs error path. git-remote-gitlawb no longer
depends on icaptcha-client.
- [beardthelion P1] Sanitize and length-bound iCaptcha error bodies before they
reach the terminal. The origin is only as trusted as the node that advertised
it, so its non-2xx bodies (and Failed{reason}) are attacker-influenceable; they
went raw into bail! (CWE-150, the #137 class). Now bounded-read + C0/C1-stripped
+ capped, same shape as #137.
- [beardthelion P2] Do not trust or hand credentials to a node-chosen iCaptcha
URL. x-icaptcha-url was used as the base with no scheme/host check and the API
key was sent to it on the first hop (SSRF + key exfiltration). resolve_solver_url
now honors an advertised URL only when https + host-allowlisted (public default
or the operator's GITLAWB_ICAPTCHA_URL), else falls back to the trusted origin;
the API key is attached only to the operator's own configured origin.
- [jatmn P2 / CodeRabbit] gl repo clone with a bare name now derives the short
owner key via resolve_owner_did, matching the other commands' gitlawb://z.../name
URL shape instead of the colon-bearing full DID.
Skipped (with reason): jatmn P3 (doctor GITLAWB_ICAPTCHA_URL) is resolved by the
P2 change — that env var is now read by the write path, so the doctor's probe is
accurate. CodeRabbit User-Agent-version nit lived in the push code reverted to
main. README push wording kept ("signed-only, no per-push challenge") — now
accurate since the retry path is gone; the API-key bullet was updated for the new
trust model.
Tests: added sanitize + resolve_solver_url unit tests; full workspace green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>1 parent 2df6ff9 commit 06388ec
12 files changed
Lines changed: 989 additions & 84 deletions
File tree
- crates
- gitlawb-node/src
- gl
- src
- icaptcha-client
- src
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
9 | 10 | | |
10 | 11 | | |
11 | 12 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
185 | 185 | | |
186 | 186 | | |
187 | 187 | | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
188 | 227 | | |
189 | 228 | | |
190 | 229 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
26 | | - | |
27 | | - | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
28 | 34 | | |
29 | 35 | | |
30 | 36 | | |
| |||
44 | 50 | | |
45 | 51 | | |
46 | 52 | | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
47 | 81 | | |
48 | 82 | | |
49 | 83 | | |
| |||
58 | 92 | | |
59 | 93 | | |
60 | 94 | | |
61 | | - | |
62 | | - | |
63 | | - | |
64 | | - | |
65 | | - | |
66 | | - | |
67 | | - | |
68 | | - | |
69 | | - | |
| 95 | + | |
| 96 | + | |
70 | 97 | | |
71 | 98 | | |
72 | 99 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
237 | 237 | | |
238 | 238 | | |
239 | 239 | | |
240 | | - | |
241 | | - | |
242 | | - | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
243 | 247 | | |
244 | 248 | | |
245 | 249 | | |
| |||
265 | 269 | | |
266 | 270 | | |
267 | 271 | | |
268 | | - | |
269 | | - | |
270 | | - | |
271 | | - | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
272 | 289 | | |
273 | 290 | | |
274 | 291 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
| 15 | + | |
15 | 16 | | |
16 | 17 | | |
17 | 18 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
174 | 174 | | |
175 | 175 | | |
176 | 176 | | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
177 | 190 | | |
178 | 191 | | |
179 | 192 | | |
| |||
191 | 204 | | |
192 | 205 | | |
193 | 206 | | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
194 | 232 | | |
195 | 233 | | |
196 | 234 | | |
| |||
0 commit comments