{"thread":{"id":"18239","subject":"[PATCH][v2] http authentication via prompts (with correct line lengths)","startedAt":"2009-03-10T00:08:07Z","lastAt":"2009-03-14T06:43:19Z","messageCount":20,"participants":["Mike Gaffney","Junio C Hamano","Johannes Schindelin","Daniel Stenberg","Mike Ralphson"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"107526","messageId":"49B5AF67.6050508@gmail.com","threadId":"18239","inReplyTo":null,"subject":"[PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Mike Gaffney","fromEmail":"mr.gaffo@gmail.com","sentAt":"2009-03-10T00:08:07Z","receivedAt":"2009-03-10T00:08:07Z","isPatch":true,"sender":{"key":"mr.gaffo@gmail.com","avatar":"https://gravatar.com/avatar/5af46a60cbd83f2ddb0c2cf4d02b91db42fd25e2ac568ff0d71f699d852ee79d?d=mp&s=160"},"body":"Currently git over http only works with a .netrc file which required\nthat you store your password on the file system in plaintext. This\ncommit adds to configuration options for http for a username and an\noptional password. If a http.username is set, then the .netrc file\nis ignored and the username is used instead. If a http.password is\nset, then that is used as well, otherwise the user is prompted for\ntheir password.\n\nWith the old .netrc working, this patch provides backwards\ncompatibility while adding a more secure option for users whose\nhttp password may be sensitive (such as if its a domain controller\npassword) and do not wish to have it on the filesystem.\n\nSigned-off-by: Mike Gaffney <mike@uberu.com>\n---\n Documentation/config.txt                           |    7 +++\n Documentation/howto/setup-git-server-over-http.txt |   38 ++++++++++++++++--\n http.c                                             |   41 ++++++++++++++++++-\n http.h                                             |    2 +\n 4 files changed, 81 insertions(+), 7 deletions(-)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex f5152c5..821bf48 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -920,6 +920,13 @@ help.autocorrect::\n \tvalue is 0 - the command will be just shown but not executed.\n \tThis is the default.\n \n+http.username, http.password:\n+    The username and password for http authentication. http.username is\n+    required, http.password is optional. If supplied, the .netrc file will\n+    be ignored. If a password is not supplied, git will prompt for it.\n+    Be careful when configuring a password as it will be stored in plain text\n+    on the filesystem.\n+\n http.proxy::\n \tOverride the HTTP proxy, normally configured using the 'http_proxy'\n \tenvironment variable (see linkgit:curl[1]).  This can be overridden\ndiff --git a/Documentation/howto/setup-git-server-over-http.txt b/Documentation/howto/setup-git-server-over-http.txt\nindex 622ee5c..462a9d4 100644\n--- a/Documentation/howto/setup-git-server-over-http.txt\n+++ b/Documentation/howto/setup-git-server-over-http.txt\n@@ -189,8 +189,19 @@ Make sure that you have HTTP support, i.e. your git was built with\n libcurl (version more recent than 7.10). The command 'git http-push' with\n no argument should display a usage message.\n \n-Then, add the following to your $HOME/.netrc (you can do without, but will be\n-asked to input your password a _lot_ of times):\n+There are 2 ways to authenticate with git http, netrc and via the git config.\n+The netrc option requires that you put the username and password for the connection\n+in $HOME/.netrc. The configuration method allows you to specify a username and\n+optionally a password. If the password is not supplied then git will prompt you\n+for the password. The downside to the netrc method is that you must have your\n+username and password in plaintext on the filesystem, albeit in a protected file.\n+If the username/password combo is a sensitive one, you may wish to use the\n+git config method. The downside of the config method is that you will be prompted\n+for your password every time you push or pull to the remote repository.\n+\n+Using netrc:\n+\n+Using your favourite ext editor, add the following to your $HOME/.netrc:\n \n     machine <servername>\n     login <username>\n@@ -204,7 +215,7 @@ instead of the server name.\n \n To check whether all is OK, do:\n \n-   curl --netrc --location -v http://<username>@<servername>/my-new-repo.git/HEAD\n+   curl --netrc --location -v http://<servername>/my-new-repo.git/HEAD\n \n ...this should give something like 'ref: refs/heads/master', which is\n the content of the file HEAD on the server.\n@@ -213,12 +224,31 @@ Now, add the remote in your existing repository which contains the project\n you want to export:\n \n    $ git-config remote.upload.url \\\n-       http://<username>@<servername>/my-new-repo.git/\n+       http://<servername>/my-new-repo.git/\n \n It is important to put the last '/'; Without it, the server will send\n a redirect which git-http-push does not (yet) understand, and git-http-push\n will repeat the request infinitely.\n \n+Using git config:\n+\n+curl --user <username>:<password> --location -v http://<servername>/my-new-repo.git/HEAD\n+\n+...this should give something like 'ref: refs/heads/master', which is\n+the content of the file HEAD on the server.\n+\n+Now, add the remote in your existing repository which contains the project\n+you want to export:\n+\n+   $ git-config remote.upload.url \\\n+       http://<servername>/my-new-repo.git/\n+\n+Also, add in your username with:\n+   $ git-config http.username <username>\n+\n+And optionally your password (you will be prompted for it if you do not):\n+   $ git-config http.password <password>\n+\n \n Step 4: make the initial push\n -----------------------------\ndiff --git a/http.c b/http.c\nindex ee58799..348b9fb 100644\n--- a/http.c\n+++ b/http.c\n@@ -26,6 +26,9 @@ static long curl_low_speed_time = -1;\n static int curl_ftp_no_epsv = 0;\n static const char *curl_http_proxy = NULL;\n \n+static const char *curl_http_username = NULL;\n+static const char *curl_http_password = NULL;\n+\n static struct curl_slist *pragma_header;\n \n static struct active_request_slot *active_queue_head = NULL;\n@@ -153,11 +156,45 @@ static int http_options(const char *var, const char *value, void *cb)\n \t\t\treturn git_config_string(&curl_http_proxy, var, value);\n \t\treturn 0;\n \t}\n+\tif (!strcmp(\"http.username\", var)) {\n+\t\tif (curl_http_username == NULL)\n+\t\t{\n+\t\t\treturn git_config_string(&curl_http_username, var, value);\n+\t\t}\n+\t\treturn 0;\n+\t}\n+\tif (!strcmp(\"http.password\", var)) {\n+\t\tif (curl_http_password == NULL)\n+\t\t{\n+\t\t\treturn git_config_string(&curl_http_password, var, value);\n+\t\t}\n+\t\treturn 0;\n+\t}\n \n \t/* Fall back on the default ones */\n \treturn git_default_config(var, value, cb);\n }\n \n+static void init_curl_http_auth(CURL* result){\n+#if LIBCURL_VERSION_NUM >= 0x070907\n+        struct strbuf userpass;\n+        strbuf_init(&userpass, 0);\n+        if (curl_http_username != NULL) {\n+                strbuf_addstr(&userpass, curl_http_username);\n+\t\tstrbuf_addstr(&userpass, \":\");\n+\t\tif (curl_http_password != NULL) {\n+\t\t\tstrbuf_addstr(&userpass, curl_http_password);\n+\t\t} else {\n+\t\t\tstrbuf_addstr(&userpass, getpass(\"Password: \"));\n+\t\t}\n+\t\tcurl_easy_setopt(result, CURLOPT_USERPWD, userpass.buf);\n+\t\tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_IGNORED);\n+        } else {\n+\t\tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n+        }\n+#endif\n+}\n+\n static CURL* get_curl_handle(void)\n {\n \tCURL* result = curl_easy_init();\n@@ -172,9 +209,7 @@ static CURL* get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 2);\n \t}\n \n-#if LIBCURL_VERSION_NUM >= 0x070907\n-\tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n-#endif\n+        init_curl_http_auth(result);\n \n \tif (ssl_cert != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\ndiff --git a/http.h b/http.h\nindex 905b462..71320d1 100644\n--- a/http.h\n+++ b/http.h\n@@ -5,6 +5,8 @@\n \n #include <curl/curl.h>\n #include <curl/easy.h>\n+#include <termios.h>\n+#include <stdio.h>\n \n #include \"strbuf.h\"\n #include \"remote.h\"\n-- \n1.6.1.2\n"},{"id":"107531","messageId":"7v1vt6dxg9.fsf@gitster.siamese.dyndns.org","threadId":"18239","inReplyTo":"49B5AF67.6050508@gmail.com","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2009-03-10T00:37:58Z","receivedAt":"2009-03-10T00:37:58Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"It appears that none of the issues I raised in my response to your earlier\nround was addressed in this patch, except for the line rewrapping of the\nproposed commit log message.\n"},{"id":"107533","messageId":"alpine.DEB.1.00.0903100143550.6358@intel-tinevez-2-302","threadId":"18239","inReplyTo":"7v1vt6dxg9.fsf@gitster.siamese.dyndns.org","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2009-03-10T00:45:53Z","receivedAt":"2009-03-10T00:45:53Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Mon, 9 Mar 2009, Junio C Hamano wrote:\n\n> It appears that none of the issues I raised in my response to your \n> earlier round was addressed in this patch, except for the line \n> rewrapping of the proposed commit log message.\n\nAFAICT my concerns were not addressed either: misleading subject unless \nthe patch is split into two, remote specific config variable instead of \nglobal one, security issues.\n\nCiao,\nDscho\n"},{"id":"299092","messageId":"49B5DDA6.8070108@gmail.com","threadId":"18239","inReplyTo":"alpine.DEB.1.00.0903100143550.6358@intel-tinevez-2-302","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Mike Gaffney","fromEmail":"mr.gaffo@gmail.com","sentAt":"2009-03-10T03:25:26Z","receivedAt":"2009-03-10T03:25:26Z","isPatch":true,"sender":{"key":"mr.gaffo@gmail.com","avatar":"https://gravatar.com/avatar/5af46a60cbd83f2ddb0c2cf4d02b91db42fd25e2ac568ff0d71f699d852ee79d?d=mp&s=160"},"body":"I guess it makes sense to split the config out into two patches. I wanted both to help with automated builds, and as it's a read only account I wasn't worried about someone reading the password. I'm not very impressed with the permissions on the .netrc file actually providing security so I can see not allowing the password in the config either. In my system at work, we have shared machines but all developers have root access, so file permissions don't really secure anything for us. It's also why we can't really use keys (there is no way to enforce that a key is secured afaik).\n\nI wanted to do a remote specific config as well but a global works well in many environments where your push repo is under http as you don't keep having to configure it. I also couldn't see a good way to do a remote specific config without changing the remote struct (which seemd like putting specific in a general). I would love some advice on this and where to put it.\n\nI can see your security points but I would argue that if that's what we are worried about then we should not allow the netrc file at all. I added notes in the config documentation about this. I'm open to discussion on this point.\n\nJohannes Schindelin wrote:\n> Hi,\n> \n> On Mon, 9 Mar 2009, Junio C Hamano wrote:\n> \n>> It appears that none of the issues I raised in my response to your \n>> earlier round was addressed in this patch, except for the line \n>> rewrapping of the proposed commit log message.\n> \n> AFAICT my concerns were not addressed either: misleading subject unless \n> the patch is split into two, remote specific config variable instead of \n> global one, security issues.\n> \n> Ciao,\n> Dscho\n> \n\n-- \n-Mike Gaffney (http://rdocul.us)\n"},{"id":"107539","messageId":"49B5F0BA.3070806@gmail.com","threadId":"18239","inReplyTo":"7v1vt6dxg9.fsf@gitster.siamese.dyndns.org","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Mike Gaffney","fromEmail":"mr.gaffo@gmail.com","sentAt":"2009-03-10T04:46:50Z","receivedAt":"2009-03-10T04:46:50Z","isPatch":true,"sender":{"key":"mr.gaffo@gmail.com","avatar":"https://gravatar.com/avatar/5af46a60cbd83f2ddb0c2cf4d02b91db42fd25e2ac568ff0d71f699d852ee79d?d=mp&s=160"},"body":"Junio,\n\tJust spent about 30 minutes replying to your points until the last one\nmade most moot. I agree that putting the info into the url will fix the bug, \nwhich I have never seen (see #3 below), and make the howto easier to read. So a \nfew things I wanted to discuss or ask for help on:\n\n1) Note that I'm not a C guy so:\n\nJunio wrote:\n>> +static const char *curl_http_username = NULL;\n>> +static const char *curl_http_password = NULL;\n>> +\n> Please do not introduce new initializations of static variables to 0 or\n> NULL.  As a clean-up, before your patch, you can send in a patch to fix\n> existing such initializations.\n\nI'm not sure what you mean here. Should I just declare them as:\nstatic const char *curl_http_password; ?\n\nAlso do you mean that during after the patch phase they get changed to:\nstatic const char *curl_http_password = NULL; ?\n\nOr do you mean that I can send in a patch to fix other static variables\n(not mine) which are being initialized to NULL?\n\n2) Being that I'm not a big C guy, I'm not sure the best way to go about \nparsing the username out of the URL to pull it into a variable to pass\nto CURLOPT_USERPASS. Any advice from the community would be greatly\nappreciated.\n\n3) From my experience with curl, many of the options do\nnot work the same across versions or platforms. For example, the new\nCURLOPT_USERNAME/PASSWORD options worked fine in 7.19.4 on cygwin but not\non FC9, which is why I used the older USERPWD. Also, my curl never prompted\nme for the password when I supplied a username in the URL which is what \nprompted me to do this patch in the first place. As such, I think it is\nbetter to pull the username & password prompting logic into git make this \nstable and fix the bug. \n\n4) I'm not really impressed that file permissions actually make the .netrc\nfile a secure option. However, it's already in there and would break\nbackwards compatibility to take it out. I also realize that there is a need\nfor automated builds to be able to pull the source. So I would like to add a nice \nwarning section to the http docs explaining the repercussions of using it.\n\nThanks for the help,\n\tMike\n"},{"id":"107543","messageId":"7v63ihdgy6.fsf@gitster.siamese.dyndns.org","threadId":"18239","inReplyTo":"49B5F0BA.3070806@gmail.com","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2009-03-10T06:34:25Z","receivedAt":"2009-03-10T06:34:25Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Mike Gaffney <mr.gaffo@gmail.com> writes:\n\n>>> +static const char *curl_http_username = NULL;\n>>> +static const char *curl_http_password = NULL;\n>>> +\n>> Please do not introduce new initializations of static variables to 0 or\n>> NULL.  As a clean-up, before your patch, you can send in a patch to fix\n>> existing such initializations.\n> ...\n> Or do you mean that I can send in a patch to fix other static variables\n> (not mine) which are being initialized to NULL?\n\nYeah, a preparatory patch to clean things up, like the one I sent out\nearlier this evening, was what I meant.\n\n> 2) Being that I'm not a big C guy, I'm not sure the best way to go about \n> parsing the username out of the URL to pull it into a variable to pass\n> to CURLOPT_USERPASS. Any advice from the community would be greatly\n> appreciated.\n\nI am sort of a C guy, but I am by no means a libcurl person.  A quick and\ndirty patch is attached, which is partly based on yours, but is stripped\nof version dependency and also I suspect it handles only the http-walker\nside.  It is on top of the two clean-up patch I sent this evening.\n\nIt hasn't seen any test, but I just ran this once:\n\n    $ git clone http://junio@my.private.machine/test-repo.git/\n\nfrom a repository that requires authentication but I have no .netrc and no\nhttp.password configuration; I was asked for the password once, of course.\n\n> 3) From my experience with curl, many of the options do\n> not work the same across versions or platforms. For example, the new\n> CURLOPT_USERNAME/PASSWORD options worked fine in 7.19.4 on cygwin but not\n> on FC9, which is why I used the older USERPWD. Also, my curl never prompted\n> me for the password when I supplied a username in the URL which is what \n> prompted me to do this patch in the first place. As such, I think it is\n> better to pull the username & password prompting logic into git make this \n> stable and fix the bug. \n\nHeh, 7.19.4 was only released on a few days ago if I am reading its\ndownload page correctly.\n\nThe version of libcurl on my box is 7.18.something, and it does not seem\nto ask for password when the URL has only username but not colon-password.\nI also expected it to ask for password when $HOME/.netrc has login but not\npassword for a given machine, but that does not seem to happen either.\nPerhaps the version is too old.\n\n> 4) I'm not really impressed that file permissions actually make the .netrc\n> file a secure option. However, it's already in there and would break\n> backwards compatibility to take it out. I also realize that there is a need\n> for automated builds to be able to pull the source. So I would like to add a nice \n> warning section to the http docs explaining the repercussions of using it.\n\nI agree with the first two sentences and am not happy with http.password\nbecause of it.\n\n\n---\n http.c |   60 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++\n 1 files changed, 60 insertions(+), 0 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex f4f0bf6..3d5caa6 100644\n--- a/http.c\n+++ b/http.c\n@@ -25,6 +25,7 @@ static long curl_low_speed_limit = -1;\n static long curl_low_speed_time = -1;\n static int curl_ftp_no_epsv;\n static const char *curl_http_proxy;\n+static char *user_name, *user_pass;\n \n static struct curl_slist *pragma_header;\n \n@@ -135,6 +136,20 @@ static int http_options(const char *var, const char *value, void *cb)\n \treturn git_default_config(var, value, cb);\n }\n \n+static void init_curl_http_auth(CURL *result)\n+{\n+\tif (!user_name)\n+\t\tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n+\telse {\n+\t\tstruct strbuf up = STRBUF_INIT;\n+\t\tif (!user_pass)\n+\t\t\tuser_pass = xstrdup(getpass(\"Password: \"));\n+\t\tstrbuf_addf(&up, \"%s:%s\", user_name, user_pass);\n+\t\tcurl_easy_setopt(result, CURLOPT_USERPWD,\n+\t\t\t\t strbuf_detach(&up, NULL));\n+\t}\n+}\n+\n static CURL *get_curl_handle(void)\n {\n \tCURL *result = curl_easy_init();\n@@ -153,6 +168,8 @@ static CURL *get_curl_handle(void)\n \tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n #endif\n \n+\tinit_curl_http_auth(result);\n+\n \tif (ssl_cert != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n #if LIBCURL_VERSION_NUM >= 0x070902\n@@ -190,6 +207,46 @@ static CURL *get_curl_handle(void)\n \treturn result;\n }\n \n+static void http_auth_init(const char *url)\n+{\n+\tchar *at, *colon, *cp, *slash;\n+\tint len;\n+\n+\tcp = strstr(url, \"://\");\n+\tif (!cp)\n+\t\treturn;\n+\n+\t/*\n+\t * Ok, the URL looks like \"proto://something\".  Which one?\n+\t * \"proto://<user>:<pass>@<host>/...\",\n+\t * \"proto://<user>@<host>/...\", or just\n+\t * \"proto://<host>/...\"?\n+\t */\n+\tcp += 3;\n+\tat = strchr(cp, '@');\n+\tcolon = strchr(cp, ':');\n+\tslash = strchrnul(cp, '/');\n+\tif (!at || slash <= at)\n+\t\treturn; /* No credentials */\n+\tif (!colon || at <= colon) {\n+\t\t/* Only username */\n+\t\tlen = at - cp;\n+\t\tuser_name = xmalloc(len + 1);\n+\t\tmemcpy(user_name, cp, len);\n+\t\tuser_name[len] = '\\0';\n+\t\tuser_pass = NULL;\n+\t} else {\n+\t\tlen = colon - cp;\n+\t\tuser_name = xmalloc(len + 1);\n+\t\tmemcpy(user_name, cp, len);\n+\t\tuser_name[len] = '\\0';\n+\t\tlen = at - (colon + 1);\n+\t\tuser_pass = xmalloc(len + 1);\n+\t\tmemcpy(user_pass, colon + 1, len);\n+\t\tuser_pass[len] = '\\0';\n+\t}\n+}\n+\n void http_init(struct remote *remote)\n {\n \tchar *low_speed_limit;\n@@ -252,6 +309,9 @@ void http_init(struct remote *remote)\n \tif (getenv(\"GIT_CURL_FTP_NO_EPSV\"))\n \t\tcurl_ftp_no_epsv = 1;\n \n+\tif (remote && remote->url && remote->url[0])\n+\t\thttp_auth_init(remote->url[0]);\n+\n #ifndef NO_CURL_EASY_DUPHANDLE\n \tcurl_default = get_curl_handle();\n #endif\n"},{"id":"107551","messageId":"alpine.DEB.1.10.0903100905050.14797@yvahk2.pbagnpgbe.fr","threadId":"18239","inReplyTo":"7v63ihdgy6.fsf@gitster.siamese.dyndns.org","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2009-03-10T08:08:58Z","receivedAt":"2009-03-10T08:08:58Z","isPatch":true,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Mon, 9 Mar 2009, Junio C Hamano wrote:\n\n> The version of libcurl on my box is 7.18.something, and it does not seem to \n> ask for password when the URL has only username but not colon-password. I \n> also expected it to ask for password when $HOME/.netrc has login but not \n> password for a given machine, but that does not seem to happen either. \n> Perhaps the version is too old.\n\nNo, that's entirely expected. libcurl has no \"prompt the user if no password \nwas given\" logic but instead delegates that work to the application.\n\nThere was once functionality for this (removed in October 2003) but it was \nbroken and violated internal guidelines so we cut out and threw that code \naway.\n\nMore recently there have been people interested in re-implementing this \"the \nright way\" but so far it hasn't been made and thus the application is left to \nperform this task.\n\n-- \n\n  / daniel.haxx.se\n"},{"id":"107554","messageId":"7v1vt5bwsn.fsf@gitster.siamese.dyndns.org","threadId":"18239","inReplyTo":"alpine.DEB.1.10.0903100905050.14797@yvahk2.pbagnpgbe.fr","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2009-03-10T08:35:04Z","receivedAt":"2009-03-10T08:35:04Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Daniel Stenberg <daniel@haxx.se> writes:\n\n> On Mon, 9 Mar 2009, Junio C Hamano wrote:\n>\n>> The version of libcurl on my box is 7.18.something, and it does not\n>> seem to ask for password when the URL has only username but not\n>> colon-password. I also expected it to ask for password when\n>> $HOME/.netrc has login but not password for a given machine, but\n>> that does not seem to happen either. Perhaps the version is too old.\n>\n> No, that's entirely expected. libcurl has no \"prompt the user if no\n> password was given\" logic but instead delegates that work to the\n> application.\n>\n> There was once functionality for this (removed in October 2003) but it\n> was broken and violated internal guidelines so we cut out and threw\n> that code away.\n>\n> More recently there have been people interested in re-implementing\n> this \"the right way\" but so far it hasn't been made and thus the\n> application is left to perform this task.\n\nIt's always nice to find _the_ area expert around ;-)\n\nI somehow misread the description on CURLOPT_NETRC that appears in\nhttp://curl.haxx.se/libcurl/c/curl_easy_setopt.html:\n\n\tlibcurl uses a user name (and supplied or prompted password)\n\tsupplied with CURLOPT_USERPWD in preference to any of the options\n\tcontrolled by this parameter.\n\nespecially the \"or prompted password\" part to mean that unless supplied to\nthe library by the caller the library would prompt the user and obtain the\npassword.\n\nThanks for clarification.\n"},{"id":"107562","messageId":"alpine.DEB.1.00.0903101132360.14295@intel-tinevez-2-302","threadId":"18239","inReplyTo":"49B5DDA6.8070108@gmail.com","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2009-03-10T10:43:30Z","receivedAt":"2009-03-10T10:43:30Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Mon, 9 Mar 2009, Mike Gaffney wrote:\n\n> I guess it makes sense to split the config out into two patches.\n\nI guess, too, because it has been asked for.  I guess that since nobody \ncontradicted that wish, it would make sense, I guess.\n\n> I wanted both to help with automated builds, and as it's a read only \n> account I wasn't worried about someone reading the password. I'm not \n> very impressed with the permissions on the .netrc file actually \n> providing security so I can see not allowing the password in the config \n> either.\n\nIf Git were written for you, for that very specific setup, then yes, I can \nsee that one does not need to care about storing passwords in plaintext \nfiles _there_.\n\nHowever, in addition to you, Git was written for some others, too.\n\nAnd $HOME/.netrc is a well established paradigm, many programs check the \npermissions and flatly refuse to run with a big red warning if the \npermissions are not set restrictively.  So there is definitely a big, \nhuge, vast difference between storing passwords in $HOME/.netrc and \nstoring them in .git/config.\n\n> In my system at work, we have shared machines but all developers have \n> root access, so file permissions don't really secure anything for us. \n> It's also why we can't really use keys (there is no way to enforce that \n> a key is secured afaik).\n\nAgain, happily the Git team decided that in addition to you, we want to \nsupport other users.  For example us.\n\nAnd we _do_ work on computers where only trustworthy people have root \naccess.\n\n> I wanted to do a remote specific config as well but a global works well \n> in many environments where your push repo is under http as you don't \n> keep having to configure it.\n\nIMHO in this case, \"works well\" does not mean the same as \"makes sense\" at \nall.\n\nAgain, Git was written for other people, too.\n\nIt should not be necessary to say more, but here I go: on two projects I \nhave to push to multiple HTTP servers, and I do have different passwords \nthere.\n\nHowever, I am pretty convinced that it is a good idea to have the \npasswords in $HOME/.netrc where they belong instead of in a config where \nit is all too easy to fsck up the permissions.\n\nBTW that is another reason (in addition to it just being good style, \nseparating different issues into different patches) why I want you to \nsplit the patch: to reject something insecure (storing passwords in \nconfig) and to accept the secure part (reading passwords interactively \nfrom the console).\n\n> I also couldn't see a good way to do a remote specific config without \n> changing the remote struct (which seemd like putting specific in a \n> general). I would love some advice on this and where to put it.\n\nUmm.  Into the remote struct?\n\n> I can see your security points but I would argue that if that's what we \n> are worried about then we should not allow the netrc file at all.\n\nSee above.\n\n> I added notes in the config documentation about this. I'm open to \n> discussion on this point.\n\nOh, so you mean you will address my concerns?  That's good, as I am \nlooking forward to your answers to them.\n\nCiao,\nDscho\n"},{"id":"107588","messageId":"49B6885D.9020702@gmail.com","threadId":"18239","inReplyTo":"alpine.DEB.1.00.0903101132360.14295@intel-tinevez-2-302","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Mike Gaffney","fromEmail":"mr.gaffo@gmail.com","sentAt":"2009-03-10T15:33:49Z","receivedAt":"2009-03-10T15:33:49Z","isPatch":true,"sender":{"key":"mr.gaffo@gmail.com","avatar":"https://gravatar.com/avatar/5af46a60cbd83f2ddb0c2cf4d02b91db42fd25e2ac568ff0d71f699d852ee79d?d=mp&s=160"},"body":"Johannes,\n\tYour points make sense, thank you for clarifying, it helps \nme understand what the underlying concerns are. The attitude doesn't really \nhelp.\n\tDoes Junio's counter solution where git would prompt for the\npassword if the username contained a url solve your concerns with unsecure\nconfig variables? The patch would be just a bugfix to current functionality.\n\tAlso, libcurl does not warn you that you have an insecure netrc file.\nJust tried it with 7.19.4 on cygwin and FC9.\n\nThanks for the feedback,\n\tMike\n"},{"id":"107782","messageId":"e2b179460903120153u5fdb58b6tf3027eea23673df0@mail.gmail.com","threadId":"18239","inReplyTo":"7v63ihdgy6.fsf@gitster.siamese.dyndns.org","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Mike Ralphson","fromEmail":"mike.ralphson@gmail.com","sentAt":"2009-03-12T08:53:20Z","receivedAt":"2009-03-12T08:53:20Z","isPatch":true,"sender":{"key":"mike.ralphson@gmail.com","avatar":"https://avatars.githubusercontent.com/u/21603?v=4"},"body":"2009/3/10 Junio C Hamano <gitster@pobox.com>:\n> diff --git a/http.c b/http.c\n> index f4f0bf6..3d5caa6 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -25,6 +25,7 @@ static long curl_low_speed_limit = -1;\n>  static long curl_low_speed_time = -1;\n>  static int curl_ftp_no_epsv;\n>  static const char *curl_http_proxy;\n> +static char *user_name, *user_pass;\n>\n>  static struct curl_slist *pragma_header;\n>\n> @@ -135,6 +136,20 @@ static int http_options(const char *var, const char *value, void *cb)\n>        return git_default_config(var, value, cb);\n>  }\n>\n> +static void init_curl_http_auth(CURL *result)\n> +{\n> +       if (!user_name)\n> +               curl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n> +       else {\n> +               struct strbuf up = STRBUF_INIT;\n> +               if (!user_pass)\n> +                       user_pass = xstrdup(getpass(\"Password: \"));\n> +               strbuf_addf(&up, \"%s:%s\", user_name, user_pass);\n> +               curl_easy_setopt(result, CURLOPT_USERPWD,\n> +                                strbuf_detach(&up, NULL));\n> +       }\n> +}\n> +\n\nElsewhere we seem to protect use of CURL_NETRC_OPTIONAL by checking\nfor LIBCURL_VERSION_NUM >= 0x070907. I have an ancient curl here\n(curl-7.9.3-2ssl) which doesn't seem to have this option, so building\nnext is broken on AIX for me from this morning (c33976cb).\n\nIs there a specific minimum version of curl we want to continue supporting?\n\nMike\n"},{"id":"107783","messageId":"alpine.DEB.1.10.0903120956460.18527@yvahk2.pbagnpgbe.fr","threadId":"18239","inReplyTo":"e2b179460903120153u5fdb58b6tf3027eea23673df0@mail.gmail.com","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2009-03-12T08:59:34Z","receivedAt":"2009-03-12T08:59:34Z","isPatch":true,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Thu, 12 Mar 2009, Mike Ralphson wrote:\n\n> Elsewhere we seem to protect use of CURL_NETRC_OPTIONAL by checking for \n> LIBCURL_VERSION_NUM >= 0x070907. I have an ancient curl here \n> (curl-7.9.3-2ssl) which doesn't seem to have this option, so building next \n> is broken on AIX for me from this morning (c33976cb).\n>\n> Is there a specific minimum version of curl we want to continue supporting?\n\nMay I suggest perhaps require a libcurl version that is no older than three \nyears or something like that?\n\nPerhaps this list can serve as some help:\n\n \thttp://curl.haxx.se/docs/releases.html\n\n(spoiler: libcurl 7.9.3 is more than seven years old!)\n\n-- \n\n  / daniel.haxx.se\n"},{"id":"107785","messageId":"e2b179460903120212x67081f69wb66364918714add7@mail.gmail.com","threadId":"18239","inReplyTo":"alpine.DEB.1.10.0903120956460.18527@yvahk2.pbagnpgbe.fr","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Mike Ralphson","fromEmail":"mike.ralphson@gmail.com","sentAt":"2009-03-12T09:12:11Z","receivedAt":"2009-03-12T09:12:11Z","isPatch":true,"sender":{"key":"mike.ralphson@gmail.com","avatar":"https://avatars.githubusercontent.com/u/21603?v=4"},"body":"2009/3/12 Daniel Stenberg <daniel@haxx.se>:\n> On Thu, 12 Mar 2009, Mike Ralphson wrote:\n>\n>> Elsewhere we seem to protect use of CURL_NETRC_OPTIONAL by checking for\n>> LIBCURL_VERSION_NUM >= 0x070907. I have an ancient curl here\n>> (curl-7.9.3-2ssl) which doesn't seem to have this option, so building next\n>> is broken on AIX for me from this morning (c33976cb).\n>>\n>> Is there a specific minimum version of curl we want to continue\n>> supporting?\n>\n> May I suggest perhaps require a libcurl version that is no older than three\n> years or something like that?\n\nIt might be a plan 8-) Though I was thinking technically in terms of\nfeatures we think git needs. Though doubtless there are several\nsecurity fixes it would be beneficial to keep up to date with.\n\n> (spoiler: libcurl 7.9.3 is more than seven years old!)\n\nAnd still the release IBM package for AIX [1]. 8-(\n\nThe summary of automatic builds (http://curl.haxx.se/auto/) is very\nnicely presented. Is that custom code?\n\nThanks for curl, even the old versions!\n\nMike\n\n[1] http://www-03.ibm.com/systems/power/software/aix/linux/toolbox/alpha.html\n"},{"id":"107787","messageId":"alpine.DEB.1.10.0903121014010.18527@yvahk2.pbagnpgbe.fr","threadId":"18239","inReplyTo":"e2b179460903120212x67081f69wb66364918714add7@mail.gmail.com","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2009-03-12T09:24:12Z","receivedAt":"2009-03-12T09:24:12Z","isPatch":true,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Thu, 12 Mar 2009, Mike Ralphson wrote:\n\n>> May I suggest perhaps require a libcurl version that is no older than three \n>> years or something like that?\n>\n> It might be a plan 8-) Though I was thinking technically in terms of \n> features we think git needs. Though doubtless there are several security \n> fixes it would be beneficial to keep up to date with.\n\nRight, but if you set a common lowest denominator first you know what features \nto expect to be there _at least_, then there might of course be a set of \nadditional ones brought by newer versions. It would reduce the amount of \nconditionals in the code and what-if-this-is-used scenarios (in the code and \nin support/docs). It also reduces the risks of git getting odd problems due to \nvery old libcurl bugs.\n\n>> (spoiler: libcurl 7.9.3 is more than seven years old!)\n>\n> And still the release IBM package for AIX [1]. 8-(\n\nHowever, someone who's building/getting git might also be able to build/get a \nnewer libcurl.\n\n> The summary of automatic builds (http://curl.haxx.se/auto/) is very nicely \n> presented. Is that custom code?\n\nThe code is custom (perl) but present in the curl CVS repo for the web site \nand could probably fairly easy be adapted for other purposes/projects.\n\nIn the curl project we provide scripts for distributed automatic tests and \nthen we have a central server that receives the reports by mail and the \nautomatic summary script displays the status of those tests on that page.\n\n-- \n\n  / daniel.haxx.se\n"},{"id":"107905","messageId":"7vsklihsti.fsf@gitster.siamese.dyndns.org","threadId":"18239","inReplyTo":"e2b179460903120153u5fdb58b6tf3027eea23673df0@mail.gmail.com","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2009-03-13T05:53:29Z","receivedAt":"2009-03-13T05:53:29Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Mike Ralphson <mike.ralphson@gmail.com> writes:\n\n> Elsewhere we seem to protect use of CURL_NETRC_OPTIONAL by checking\n> for LIBCURL_VERSION_NUM >= 0x070907. I have an ancient curl here\n> (curl-7.9.3-2ssl) which doesn't seem to have this option, so building\n> next is broken on AIX for me from this morning (c33976cb).\n\nYeah, I did this as \"How about doing it this way without adding a band-aid\nconfiguration options\" demonstration, and meant to clean it up (rather,\nmeant to wait for the original submitter to clean-up) before moving it\nforward, but I forgot.  Sorry about that.\n\nHow does this look?\n\nhttp://curl.haxx.se/libcurl/c/curl_easy_setopt.html seems to say \"added in\n7.X.Y\" for some options but does say when CURLOPT_USERPWD was added, so I\nam assuming it was available even in very early versions...\n\n-- >8 --\nFrom 750d9305009a0f3fd14c0b5c5e62ae1eb2b18fda Mon Sep 17 00:00:00 2001\nFrom: Junio C Hamano <gitster@pobox.com>\nDate: Thu, 12 Mar 2009 22:34:43 -0700\nSubject: [PATCH] http.c: CURLOPT_NETRC_OPTIONAL is not available in ancient versions of cURL\n\nBesides, we have already called easy_setopt with the option before coming\nto this function if it was available, so there is no need to repeat it\nhere.\n\nSigned-off-by: Junio C Hamano <gitster@pobox.com>\n---\n http.c |    4 +---\n 1 files changed, 1 insertions(+), 3 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex b8f947e..2fc55d6 100644\n--- a/http.c\n+++ b/http.c\n@@ -138,9 +138,7 @@ static int http_options(const char *var, const char *value, void *cb)\n \n static void init_curl_http_auth(CURL *result)\n {\n-\tif (!user_name)\n-\t\tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n-\telse {\n+\tif (user_name) {\n \t\tstruct strbuf up = STRBUF_INIT;\n \t\tif (!user_pass)\n \t\t\tuser_pass = xstrdup(getpass(\"Password: \"));\n-- \n1.6.2.249.g770a0\n"},{"id":"107913","messageId":"alpine.DEB.1.10.0903130855240.24124@yvahk2.pbagnpgbe.fr","threadId":"18239","inReplyTo":"7vsklihsti.fsf@gitster.siamese.dyndns.org","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2009-03-13T07:58:04Z","receivedAt":"2009-03-13T07:58:04Z","isPatch":true,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Thu, 12 Mar 2009, Junio C Hamano wrote:\n\n> http://curl.haxx.se/libcurl/c/curl_easy_setopt.html seems to say \"added in \n> 7.X.Y\" for some options but does say when CURLOPT_USERPWD was added, so I am \n> assuming it was available even in very early versions...\n\nYes it was.\n\nDriven by use cases such as this, I also recently produced the \n\"symbols-in-versions\" document in the libcurl tree which should help apps to \nknow what should works when:\n\nhttp://cool.haxx.se/cvs.cgi/curl/docs/libcurl/symbols-in-versions?rev=HEAD&content-type=text/vnd.viewcvs-markup\n\n-- \n\n  / daniel.haxx.se\n"},{"id":"107930","messageId":"e2b179460903130353p1d3c1cb2n8286c2a284724156@mail.gmail.com","threadId":"18239","inReplyTo":"7vsklihsti.fsf@gitster.siamese.dyndns.org","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Mike Ralphson","fromEmail":"mike.ralphson@gmail.com","sentAt":"2009-03-13T10:53:24Z","receivedAt":"2009-03-13T10:53:24Z","isPatch":true,"sender":{"key":"mike.ralphson@gmail.com","avatar":"https://avatars.githubusercontent.com/u/21603?v=4"},"body":"2009/3/13 Junio C Hamano <gitster@pobox.com>:\n> Yeah, I did this as \"How about doing it this way without adding a band-aid\n> configuration options\" demonstration, and meant to clean it up (rather,\n> meant to wait for the original submitter to clean-up) before moving it\n> forward, but I forgot.  Sorry about that.\n>\n> How does this look?\n\nThis patch fixes the build breakage for me, thanks. If I can find a\ncombination of AIX + working gcc + correct 32bit / non-broken 64bit\nlibraries + necessary Gnu tools + ancient curl + Apache2 in this maze\nof twisty turny servers (all different) I'll give the http server\ntests a whirl too.\n\n2009/3/13 Daniel Stenberg <daniel@haxx.se>:\n>Driven by use cases such as this, I also recently produced the\n>\"symbols-in-versions\" document in the libcurl tree which should\n> help apps to know what should works when:\n\n> http://cool.haxx.se/cvs.cgi/curl/docs/libcurl/symbols-in-versions?rev=HEAD&content-type=text/vnd.viewcvs-markup\n\nVery helpful, thanks.\n\nJunio, if I check all the unprotected CURL* options against this list,\nwould that give us our absolute minimum supported version? If so,\nwould it then be ok to remove any unnecessary ifdefs for lower\nversions if they exist?\n\nMike\n"},{"id":"107938","messageId":"49BA55E2.1060604@gmail.com","threadId":"18239","inReplyTo":"7vsklihsti.fsf@gitster.siamese.dyndns.org","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Mike Gaffney","fromEmail":"mr.gaffo@gmail.com","sentAt":"2009-03-13T12:47:30Z","receivedAt":"2009-03-13T12:47:30Z","isPatch":true,"sender":{"key":"mr.gaffo@gmail.com","avatar":"https://gravatar.com/avatar/5af46a60cbd83f2ddb0c2cf4d02b91db42fd25e2ac568ff0d71f699d852ee79d?d=mp&s=160"},"body":"I was going to try and clean this up this weekend or early next week. I'm also\ntrying to encourage open source submissions at work and was using this\nas an example patch to get people going (we need the fix to use git). So\nI do plan finishing this, just have to do it when I have time.\n\nDaniel, thanks for the link, I had been wondering what was introduced when in curl.\n\n-Mike\n\nJunio C Hamano wrote:\n> Mike Ralphson <mike.ralphson@gmail.com> writes:\n> \n>> Elsewhere we seem to protect use of CURL_NETRC_OPTIONAL by checking\n>> for LIBCURL_VERSION_NUM >= 0x070907. I have an ancient curl here\n>> (curl-7.9.3-2ssl) which doesn't seem to have this option, so building\n>> next is broken on AIX for me from this morning (c33976cb).\n> \n> Yeah, I did this as \"How about doing it this way without adding a band-aid\n> configuration options\" demonstration, and meant to clean it up (rather,\n> meant to wait for the original submitter to clean-up) before moving it\n> forward, but I forgot.  Sorry about that.\n> \n> How does this look?\n> \n> http://curl.haxx.se/libcurl/c/curl_easy_setopt.html seems to say \"added in\n> 7.X.Y\" for some options but does say when CURLOPT_USERPWD was added, so I\n> am assuming it was available even in very early versions...\n> \n> -- >8 --\n> From 750d9305009a0f3fd14c0b5c5e62ae1eb2b18fda Mon Sep 17 00:00:00 2001\n> From: Junio C Hamano <gitster@pobox.com>\n> Date: Thu, 12 Mar 2009 22:34:43 -0700\n> Subject: [PATCH] http.c: CURLOPT_NETRC_OPTIONAL is not available in ancient versions of cURL\n> \n> Besides, we have already called easy_setopt with the option before coming\n> to this function if it was available, so there is no need to repeat it\n> here.\n> \n> Signed-off-by: Junio C Hamano <gitster@pobox.com>\n> ---\n>  http.c |    4 +---\n>  1 files changed, 1 insertions(+), 3 deletions(-)\n> \n> diff --git a/http.c b/http.c\n> index b8f947e..2fc55d6 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -138,9 +138,7 @@ static int http_options(const char *var, const char *value, void *cb)\n>  \n>  static void init_curl_http_auth(CURL *result)\n>  {\n> -\tif (!user_name)\n> -\t\tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n> -\telse {\n> +\tif (user_name) {\n>  \t\tstruct strbuf up = STRBUF_INIT;\n>  \t\tif (!user_pass)\n>  \t\t\tuser_pass = xstrdup(getpass(\"Password: \"));\n\n-- \n-Mike Gaffney (http://rdocul.us)\n"},{"id":"107996","messageId":"7vocw4ejh0.fsf@gitster.siamese.dyndns.org","threadId":"18239","inReplyTo":"e2b179460903130353p1d3c1cb2n8286c2a284724156@mail.gmail.com","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2009-03-14T05:55:55Z","receivedAt":"2009-03-14T05:55:55Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Mike Ralphson <mike.ralphson@gmail.com> writes:\n\n> 2009/3/13 Daniel Stenberg <daniel@haxx.se>:\n>>Driven by use cases such as this, I also recently produced the\n>>\"symbols-in-versions\" document in the libcurl tree which should\n>> help apps to know what should works when:\n>\n>> http://cool.haxx.se/cvs.cgi/curl/docs/libcurl/symbols-in-versions?rev=HEAD&content-type=text/vnd.viewcvs-markup\n>\n> Very helpful, thanks.\n\nYeah, I wish we new about it much earlier.  Thanks, Daniel.\n\n> Junio, if I check all the unprotected CURL* options against this list,\n> would that give us our absolute minimum supported version? If so,\n> would it then be ok to remove any unnecessary ifdefs for lower\n> versions if they exist?\n\nSounds like a good plan.  Please get the ball rolling.\n"},{"id":"107998","messageId":"7v3adgeha0.fsf@gitster.siamese.dyndns.org","threadId":"18239","inReplyTo":"49BA55E2.1060604@gmail.com","subject":"Re: [PATCH][v2] http authentication via prompts (with correct line lengths)","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2009-03-14T06:43:19Z","receivedAt":"2009-03-14T06:43:19Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Mike Gaffney <mr.gaffo@gmail.com> writes:\n\n> I was going to try and clean this up this weekend or early next week. I'm also\n> trying to encourage open source submissions at work and was using this\n> as an example patch to get people going (we need the fix to use git). So\n> I do plan finishing this, just have to do it when I have time.\n\nThanks.\n"}]}