Repository navigation
feat: add namespace blocking functionality for JWT authentication - #313
Merged
Merged
Conversation
Implements a denylist mechanism to block specific namespaces from publishing packages. Admins with global permissions bypass the blocking logic. This addresses namespace abuse prevention requirements. Fixes #98 🏠 Remote-Dev: homespace
🏠 Remote-Dev: homespace
🏠 Remote-Dev: homespace
🏠 Remote-Dev: homespace
domdomegg
commented
Aug 27, 2025
|
|
||
| // BlockedNamespaces contains a list of namespaces that are not allowed to publish packages. | ||
| // This is used as a denylist mechanism to prevent abuse. | ||
| var BlockedNamespaces = []string{ |
Member
Author
There was a problem hiding this comment.
note: why a file and not a database table?
- git gives us free audit, access control (e.g. 2PC via GitHub required reviews)
- we expect this list to be pretty small and infrequently updated
- do the simple thing that works: can add the db table later if needed
Member
Author
|
@claude please review |
Contributor
|
Claude finished @domdomegg's task —— View job Code Review: Namespace Blocking ImplementationOverall solid implementation with good test coverage. The approach is clean and the security logic is sound. A few observations below: Detailed Review Findings✅ StrengthsSecurity Design:
Implementation Quality:
Code Quality:
🔍 Minor ConsiderationsFile Organization (
Edge Case Handling (
Test Isolation (
🎯 Specific Code References
Recommendation: ✅ ApproveThis implementation correctly addresses issue #98 with a secure, well-tested approach. The file-based denylist is appropriate for the expected small scale and infrequent updates. |
jerome3o-anthropic
approved these changes
Aug 27, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements a denylist mechanism to prevent blocked namespaces from publishing packages:
BlockedNamespacesfield toJWTManagerstruct for maintaining the denylistGenerateTokenResponsethat checks user permissions against blocked namespaces*) bypass the blocking logicFixes #98