(We are using Stash 3.7.1)
We have a user called X Y Z (actually has three names, but this probably does not matter). Until now, his .gitconfig contained the correct name, but an incorrect e-mail address (x.z@company.com instead of xy.z@company.com) and was able to push commits to a repo which is not public and is configured (in the project) to accept commits only from a group (that he does belong to). The pushes succeeded because the username/password used for the HTTP authentication correctly mapped to the user.
I would like to avoid this kind of situation in the future. Is there a way to make Stash reject pushes containing commits which do not map to valid Stash users? (Or, preferably, Stash users with write permissions to the repo.)