ArchitectureSecurity model
Connected git accounts
A git connection has read access only. Its secret stays on the server and goes only to the provider.
You authorize Ferry on the page of the provider. Ferry gets read access only.
1 / 4
A git connection lets Ferry read your repositories. You authorize it on the page of the provider itself. See Git accounts.
Read access only
| Provider | What you authorize | Access |
|---|---|---|
| GitHub | A GitHub App that reads the repositories that you chose | contents: read, metadata: read |
| GitLab | A GitLab application | The scopes read_api and read_repository |
What the server keeps
The server keeps the private key of the app, the OAuth tokens and client secret, or a personal access token. The API never returns them.
- For a personal token, a connection shows only
token_hint: the last characters of the token. - The tokens of a GitHub App last one hour. Ferry keeps them only in memory.
- "The same host" means the same scheme, host and port as the provider. Ferry sends the token there when it clones or lists branches.
- The provider sends its answers back through your browser. Ferry accepts an answer only with a random
statethat the server gave less than one hour before. Eachstateworks one time.