git.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* How to identify the users?
@ 2013-01-31  5:52 Scott Yan
       [not found] ` <CAH5451nd81aHtaxqpkTeCNG0xpuPd8ptdxRcOgGHaYuN3Qb7WA@mail.gmail.com>
                   ` (2 more replies)
  0 siblings, 3 replies; 7+ messages in thread
From: Scott Yan @ 2013-01-31  5:52 UTC (permalink / raw)
  To: git

Hello everyone:

The user info of git client (user name and email) is set by the users
themselves, so , how to avoid userA pretend to be userB?

Git server could authentication the user, but it do nothing about the
user info of commit message.

For example:
There are 20 people of my team, and everyone can push to the public
repository(git server),
If I found some backdoor code in my project, and the commit record
shows it was committed by userA, so I ask userA: why do you do this?
but he told me: no, this is not my code, I have never committed such
thing.  ----and yes, everyone could change his user info to userA very
easily .

so... what should I do to avoid such situations?
Thanks!

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2013-01-31 10:12 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-01-31  5:52 How to identify the users? Scott Yan
     [not found] ` <CAH5451nd81aHtaxqpkTeCNG0xpuPd8ptdxRcOgGHaYuN3Qb7WA@mail.gmail.com>
2013-01-31  6:07   ` Scott Yan
2013-01-31  6:08 ` Tomas Carnecky
2013-01-31  6:10   ` Sitaram Chamarty
2013-01-31  6:53     ` Scott Yan
2013-01-31 10:12       ` Sitaram Chamarty
2013-01-31  6:16 ` Andrew Ardill

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).