Make --allow replace an upstream's configured allow-list - #67
Merged
Merged
Conversation
The --allow flags were written as Repositories:{index} configuration keys,
and configuration merges arrays by index. A flag therefore replaced only
the first entries of a list from --config, appsettings.json or the
environment, and left the rest in force: config ["studio/**", "**"] plus
--allow github=only/** still bound ["only/**", "**"].
The flags are now grouped per upstream and assigned in a post-configure
step, so an upstream named by --allow allows exactly the flag patterns.
Upstreams no flag names keep their configured list. The README now says
so.
Fixes #48
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015u9u95HXjY2mDagnzGzxK2
|
This was referenced Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Fixes #48
What was wrong
TryApplyAllowswrote each--allow name=patternflag toGitLfsCache:Upstreams:{name}:Repositories:{index}, starting at index 0. .NET configuration merges arrays by index across providers, so the flags replaced only the first N entries of a list that came from--config,appsettings.jsonor environment variables. Any entries at higher indices stayed in force.With config
["studio/**", "**"]and--allow github=only/**, the bound list was["only/**", "**"], so the proxy still allowed every repository.Change
This implements the maintainer decision on the issue:
--allowreplaces the list.TryParseAllowsgroups the flag patterns by upstream (case-insensitive, in the order typed) instead of writing configuration keys.ReplaceAllowListsruns as aPostConfigure<GitLfsCacheOptions>step and assigns each named upstream'sRepositoriesoutright. It creates the upstream if configuration didn't declare it, which matches the old behaviour of an--upstream/--allowpair on the command line. Upstreams that no--allownames keep their configured list.--allowreplaces the configured list for the upstream it names, rather than adding to it.--token-keyis out of scope, as the decision says, and keeps its index-merge behaviour.Tests
New
GitLfsCache.Tests/Tool/AllowFlagTests.cs. The test project now references the tool project, whoseAssemblyInfo.csalready grantsInternalsVisibleTofor this purpose. The tests bind options the way the tool does: a JSON configuration file with the flags applied over it.--allowsupplies 1, and the bound list is exactly that 1 entry.Checked both directions:
ReplaceAllowListschanged back to overwrite-by-index (the old merge semantics),Allow_FewerPatternsThanConfigured_ReplacesTheConfiguredListfails.🤖 Generated with Claude Code
https://claude.ai/code/session_015u9u95HXjY2mDagnzGzxK2
Generated by Claude Code