Forgejo: set per-user repository, upload and mirror limits #495

Öppen
öppnade 2026-09-24 13:01:06 +00:00 av supernaut · 1 kommentar
Ägare

Problem

ansible/roles/forgejo/templates/app.ini.j2 sets no per-user repository or upload caps. There is no [repository] MAX_CREATION_LIMIT, no [repository.upload] FILE_MAX_SIZE, and no mirror limits. With open registration, one account can create unlimited repositories and mirrors. The shared quota bounds stored bytes but not repository count or mirror churn.

Carried over from #125 (finding M3) when that issue closed.

Done when

  • MAX_CREATION_LIMIT, FILE_MAX_SIZE and mirror limits are set to values that fit the paid and trial tiers, and are documented in the runbook.
  • A test account hits each limit with a clear error.
## Problem `ansible/roles/forgejo/templates/app.ini.j2` sets no per-user repository or upload caps. There is no `[repository] MAX_CREATION_LIMIT`, no `[repository.upload] FILE_MAX_SIZE`, and no mirror limits. With open registration, one account can create unlimited repositories and mirrors. The shared quota bounds stored bytes but not repository count or mirror churn. Carried over from #125 (finding M3) when that issue closed. ## Done when - `MAX_CREATION_LIMIT`, `FILE_MAX_SIZE` and mirror limits are set to values that fit the paid and trial tiers, and are documented in the runbook. - A test account hits each limit with a clear error.
Upphovsperson
Ägare

Applied 2026-10-02 (#515). Second --check changed=0. Live: /api/v1/settings/attachment returns max_size: 100, max_files: 5. Still open for the "done when" item: a test account hitting the repo, upload and mirror limits.

Applied 2026-10-02 (#515). Second `--check` changed=0. Live: `/api/v1/settings/attachment` returns `max_size: 100, max_files: 5`. Still open for the "done when" item: a test account hitting the repo, upload and mirror limits.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#495
Ingen beskrivning angiven.