fix(actions): restore pushes to protected branches (#39564)

Use the Actions token's loaded write permission when checking
protected-branch pushes. Preserve push and force-push allowlists and add
regression coverage.

Fixes https://github.com/go-gitea/gitea/issues/39563
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: Giteabot <teabot@gitea.io>
This commit is contained in:
bircni authored and GitHub committed 2026-10-03 19:54:55 +02:00
1 parent cca466caae
commit 7641fc3a8c
9 files changed
+76 -25

No files matched your search

+1 -1
View File
@@ -190,7 +190,7 @@ func PrepareCommitFormOptions(ctx *Context, doer *user_model.User, targetRepo *r
protectionRequireSigned := false
if protectedBranch != nil {
protectedBranch.Repo = targetRepo
canPushWithProtection = protectedBranch.CanUserPush(ctx, doer)
canPushWithProtection = protectedBranch.CanUserPush(ctx, doer, doerRepoPerm)
protectionRequireSigned = protectedBranch.RequireSignedCommits
// If branch-wide push is restricted, allow direct commit when the
// URL-derived tree path matches an unprotected file pattern. The
+1 -1
View File
@@ -113,7 +113,7 @@ func ToBranch(ctx context.Context, repo *repo_model.Repository, branchName strin
return nil, err
}
bp.Repo = repo
branch.UserCanPush = bp.CanUserPush(ctx, user)
branch.UserCanPush = bp.CanUserPush(ctx, user, permission)
branch.UserCanMerge = git_model.IsUserMergeWhitelisted(ctx, bp, user.ID, permission)
}
+2 -2
View File
@@ -123,8 +123,8 @@ func isUserAllowedToPushOrForcePushInRepoBranch(ctx context.Context, user *user_
}
if pb != nil { // override previous results if there is a branch protection rule
pb.Repo = repo
pushAllowed = pb.CanUserPush(ctx, user)
forcePushAllowed = pb.CanUserForcePush(ctx, user)
pushAllowed = pb.CanUserPush(ctx, user, repoPerm)
forcePushAllowed = pb.CanUserForcePush(ctx, user, repoPerm)
}
return pushAllowed, forcePushAllowed, nil
}
+1 -1
View File
@@ -447,7 +447,7 @@ func RenameBranch(ctx context.Context, repo *repo_model.Repository, doer *user_m
if err != nil {
return "", err
}
if rule != nil && !rule.CanUserPush(ctx, doer) {
if rule != nil && !rule.CanUserPush(ctx, doer, perm) {
return "", git_model.ErrBranchIsProtected
}
+6 -1
View File
@@ -9,6 +9,7 @@ import (
"strings"
git_model "gitea.dev/models/git"
"gitea.dev/models/perm/access"
repo_model "gitea.dev/models/repo"
user_model "gitea.dev/models/user"
"gitea.dev/modules/git"
@@ -88,7 +89,11 @@ func (opts *ApplyDiffPatchOptions) Validate(ctx context.Context, repo *repo_mode
}
if protectedBranch != nil {
protectedBranch.Repo = repo
if !protectedBranch.CanUserPush(ctx, doer) {
perm, err := access.GetDoerRepoPermission(ctx, repo, doer)
if err != nil {
return err
}
if !protectedBranch.CanUserPush(ctx, doer, perm) {
return ErrUserCannotCommit{
UserName: doer.LowerName,
}
+6 -1
View File
@@ -13,6 +13,7 @@ import (
"time"
git_model "gitea.dev/models/git"
"gitea.dev/models/perm/access"
repo_model "gitea.dev/models/repo"
user_model "gitea.dev/models/user"
"gitea.dev/modules/git"
@@ -667,7 +668,11 @@ func VerifyBranchProtection(ctx context.Context, repo *repo_model.Repository, gi
protectedBranch.Repo = repo
globUnprotected := protectedBranch.GetUnprotectedFilePatterns()
globProtected := protectedBranch.GetProtectedFilePatterns()
canUserPush := protectedBranch.CanUserPush(ctx, doer)
perm, err := access.GetDoerRepoPermission(ctx, repo, doer)
if err != nil {
return err
}
canUserPush := protectedBranch.CanUserPush(ctx, doer, perm)
for _, treePath := range treePaths {
isUnprotectedFile := false
if len(globUnprotected) != 0 {