GET /api/v1/arweave/anchors (crates/gitlawb-node/src/api/arweave.rs:24-40, db/mod.rs:3836-3858) has no auth extractor and no visibility check. Sibling feeds (events.rs, stats, repo listings) gate every row per caller.
Impact: anonymous callers get repo, owner_did, ref_name, old_sha, new_sha and the Arweave/Irys tx id for anchors of private repos, which leaks branch names and commit tips.
Repro: GET /api/v1/arweave/anchors?repo=<owner-key>/<name> on a private repo returns 200 with ref names and shas.
Fix: apply the same per-row visibility gate events.rs uses (no existence leak), and add deny tests for an anonymous and a non-reader caller. Separate from #490 (negative limit).
Found in the Oct 2 2026 audit (A4) at bfc44f9.
GET /api/v1/arweave/anchors(crates/gitlawb-node/src/api/arweave.rs:24-40,db/mod.rs:3836-3858) has no auth extractor and no visibility check. Sibling feeds (events.rs, stats, repo listings) gate every row per caller.Impact: anonymous callers get
repo,owner_did,ref_name,old_sha,new_shaand the Arweave/Irys tx id for anchors of private repos, which leaks branch names and commit tips.Repro:
GET /api/v1/arweave/anchors?repo=<owner-key>/<name>on a private repo returns 200 with ref names and shas.Fix: apply the same per-row visibility gate
events.rsuses (no existence leak), and add deny tests for an anonymous and a non-reader caller. Separate from #490 (negativelimit).Found in the Oct 2 2026 audit (A4) at bfc44f9.