{"thread":{"id":"22036","subject":"[PATCH] Allow git to use any HTTP authentication method.","startedAt":"2009-12-28T10:54:06Z","lastAt":"2009-12-28T18:15:01Z","messageCount":11,"participants":["Lénaïc Huard","Martin Storsjö","Tay Ray Chuan","Matthieu Moy","Shawn O. Pearce","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"130393","messageId":"200912281154.09442.lenaic@lhuard.fr.eu.org","threadId":"22036","inReplyTo":null,"subject":"[PATCH] Allow git to use any HTTP authentication method.","fromName":"Lénaïc Huard","fromEmail":"lenaic@lhuard.fr.eu.org","sentAt":"2009-12-28T10:54:06Z","receivedAt":"2009-12-28T10:54:06Z","isPatch":true,"sender":{"key":"lenaic@lhuard.fr.eu.org","avatar":null},"body":"Hello,\n\nAs I need to access some of my git repositories behind a corporate company \nfirewall, I use the http access method. And, as I don't want my passwords to be \nsent in clear text over the network, I have configured my web server to use « \nDigest » authentication instead of the old « Basic » authentication.\nThis authentication method is now well handled by modern software.\n\nUnfortunately, current git version only handles « Basic » authentication.\nWhen attempting to access my repository, I get the following error message:\n\nerror: The requested URL returned error: 401 while accessing \nhttp://XXX@YYY.ZZ/test.git/info/refs\n\nThe web server, on its side, has refused the transaction because of the wrong \nauthentication method used:\n\nDigest: client used wrong authentication scheme `Basic': /test.git/info/refs\n\nThe attached patch makes git configure libcurl to negotiate the most suitable \nHTTP authentication method.\nThanks to that patch, I manage to clone and fetch my git repository hosted on \nmy web server requesting an authentication through the « Digest  » method.\n\nLénaïc.\n\n\nFrom 2acab3ae894c3ea835279a864e654e1c5e956e80 Mon Sep 17 00:00:00 2001\nFrom: =?UTF-8?q?L=C3=A9na=C3=AFc=20Huard?= <lenaic@lhuard.fr.eu.org>\nDate: Mon, 28 Dec 2009 10:52:35 +0100\nSubject: [PATCH] Allow git to use any HTTP authentication method.\n\nBy default, libcurl performs \"Basic\" HTTP authentication.\nThis method transmits passwords in clear text.\nlibcurl needs some settings in order to use a safest HTTP authentication\nmethod like \"Digest\" for example.\n---\n http.c |    4 ++++\n 1 files changed, 4 insertions(+), 0 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex ed6414a..2d9df76 100644\n--- a/http.c\n+++ b/http.c\n@@ -233,6 +233,10 @@ static CURL *get_curl_handle(void)\n \n \tinit_curl_http_auth(result);\n \n+#if LIBCURL_VERSION_NUM >= 0x070a06\n+\tcurl_easy_setopt(result, CURLOPT_HTTPAUTH, CURLAUTH_ANY);\n+#endif\n+\n \tif (ssl_cert != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n \tif (has_cert_password())\n-- \n1.6.5.7\n\n"},{"id":"130394","messageId":"alpine.DEB.2.00.0912281406210.5582@cone.home.martin.st","threadId":"22036","inReplyTo":"200912281154.09442.lenaic@lhuard.fr.eu.org","subject":"Re: [PATCH] Allow git to use any HTTP authentication method.","fromName":"Martin Storsjö","fromEmail":"martin@martin.st","sentAt":"2009-12-28T12:09:49Z","receivedAt":"2009-12-28T12:09:49Z","isPatch":true,"sender":{"key":"martin@martin.st","avatar":"https://avatars.githubusercontent.com/u/69727?v=4"},"body":"Hi Lénaïc,\n\nOn Mon, 28 Dec 2009, Lénaïc Huard wrote:\n\n> The attached patch makes git configure libcurl to negotiate the most suitable \n> HTTP authentication method.\n> Thanks to that patch, I manage to clone and fetch my git repository hosted on \n> my web server requesting an authentication through the « Digest  » method.\n\nSomething similar has already been queued for inclusion, and is available \nin the branch 'next', in commit b8ac923010484908d8426cb8ded5ad7e8c21a7f6. \nThe patch available there requires you to set http.authAny for the libcurl \noption to be enabled.\n\n// Martin"},{"id":"130395","messageId":"be6fef0d0912280412w58401f10n972f9198144cd580@mail.gmail.com","threadId":"22036","inReplyTo":"alpine.DEB.2.00.0912281406210.5582@cone.home.martin.st","subject":"Re: [PATCH] Allow git to use any HTTP authentication method.","fromName":"Tay Ray Chuan","fromEmail":"rctay89@gmail.com","sentAt":"2009-12-28T12:12:50Z","receivedAt":"2009-12-28T12:12:50Z","isPatch":true,"sender":{"key":"rctay89@gmail.com","avatar":"https://avatars.githubusercontent.com/u/61553?v=4"},"body":"Hi,\n\nOn Mon, Dec 28, 2009 at 8:09 PM, Martin Storsjö <martin@martin.st> wrote:\n> Hi Lénaďc,\n>\n> On Mon, 28 Dec 2009, Lénaďc Huard wrote:\n>\n>> The attached patch makes git configure libcurl to negotiate the most suitable\n>> HTTP authentication method.\n>> Thanks to that patch, I manage to clone and fetch my git repository hosted on\n>> my web server requesting an authentication through the « Digest  » method.\n>\n> Something similar has already been queued for inclusion, and is available\n> in the branch 'next', in commit b8ac923010484908d8426cb8ded5ad7e8c21a7f6.\n> The patch available there requires you to set http.authAny for the libcurl\n> option to be enabled.\n\n...or setting the environment variable GIT_HTTP_AUTH_ANY.\n\n(by the way, Martin was referring to setting http.authAny in your git\nconfiguration.)\n\n-- \nCheers,\nRay Chuan\n"},{"id":"130396","messageId":"vpqeimf9svf.fsf@bauges.imag.fr","threadId":"22036","inReplyTo":"200912281154.09442.lenaic@lhuard.fr.eu.org","subject":"Re: [PATCH] Allow git to use any HTTP authentication method.","fromName":"Matthieu Moy","fromEmail":"matthieu.moy@grenoble-inp.fr","sentAt":"2009-12-28T12:37:40Z","receivedAt":"2009-12-28T12:37:40Z","isPatch":true,"sender":{"key":"matthieu.moy@grenoble-inp.fr","avatar":"https://gravatar.com/avatar/72c8a2705971a25dfaff23cece15130d405685845d911aedd5667ace277f3fc5?d=mp&s=160"},"body":"Lénaïc Huard <lenaic@lhuard.fr.eu.org> writes:\n\n> The attached patch makes git configure libcurl to negotiate the most suitable \n> HTTP authentication method.\n\nThanks for your contribution.\n\nRead other people's reply about the need for this patch.\n\nOther than that, please read git/Documentation/SubmittingPatches in\nGit's source code. In short: inline patches, don't attach them, and\nuse Signed-Off-By to acknowledge that your patch can be legally\nincluded in Git's official version.\n\n-- \nMatthieu Moy\nhttp://www-verimag.imag.fr/~moy/\n"},{"id":"130398","messageId":"20091228153701.GA2252@spearce.org","threadId":"22036","inReplyTo":"be6fef0d0912280412w58401f10n972f9198144cd580@mail.gmail.com","subject":"Re: [PATCH] Allow git to use any HTTP authentication method.","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-12-28T15:37:01Z","receivedAt":"2009-12-28T15:37:01Z","isPatch":true,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Tay Ray Chuan <rctay89@gmail.com> wrote:\n> On Mon, Dec 28, 2009 at 8:09 PM, Martin Storsj?? <martin@martin.st> wrote:\n> > On Mon, 28 Dec 2009, L??na??c Huard wrote:\n> >\n> >> The attached patch makes git configure libcurl to negotiate the most suitable\n> >> HTTP authentication method.\n...\n> > Something similar has already been queued for inclusion, and is available\n> > in the branch 'next', in commit b8ac923010484908d8426cb8ded5ad7e8c21a7f6.\n> > The patch available there requires you to set http.authAny for the libcurl\n> > option to be enabled.\n\nUh, stupid question, but why must we enable this option?  I don't\nhave to enable something in my browser before I use digest auth to\nvisit a website, why do I need to enable it in git?\n\nHow does one use git clone with an http:// URL with digest\nauthentication?  Its not obvious to the user that you would need\nto first export an obtuse environment variable to get something\nthat should Just Work(tm).\n\nYes, I realize you may need to perform an extra HTTP request to\nstart the transaction, but why aren't we doing that?  Isn't it only\n1 additional request to discover the desired authentication method?\n\n-- \nShawn.\n"},{"id":"130399","messageId":"alpine.DEB.2.00.0912281745540.5582@cone.home.martin.st","threadId":"22036","inReplyTo":"20091228153701.GA2252@spearce.org","subject":"Re: [PATCH] Allow git to use any HTTP authentication method.","fromName":"Martin Storsjö","fromEmail":"martin@martin.st","sentAt":"2009-12-28T15:50:12Z","receivedAt":"2009-12-28T15:50:12Z","isPatch":true,"sender":{"key":"martin@martin.st","avatar":"https://avatars.githubusercontent.com/u/69727?v=4"},"body":"On Mon, 28 Dec 2009, Shawn O. Pearce wrote:\n\n> Uh, stupid question, but why must we enable this option?  I don't\n> have to enable something in my browser before I use digest auth to\n> visit a website, why do I need to enable it in git?\n> \n> How does one use git clone with an http:// URL with digest\n> authentication?  Its not obvious to the user that you would need\n> to first export an obtuse environment variable to get something\n> that should Just Work(tm).\n> \n> Yes, I realize you may need to perform an extra HTTP request to\n> start the transaction, but why aren't we doing that?  Isn't it only\n> 1 additional request to discover the desired authentication method?\n\nInitially when I added support for this, curl sessions weren't reused, so \nevery single request had to be duplicated if authentication was used, \nadding quite a bit of overhead.\n\nNow that sessions are reused properly, I tend to agree that this should be \nenabled automatically.\n\nAny other opinions on this, Tay or Junio?\n\nShould I send in a new patch that removes the http.authAny option and \nalways enables this, or send a rewritten version of the patch that already \nis in 'next'?\n\n// Martin\n"},{"id":"130400","messageId":"20091228155346.GB2252@spearce.org","threadId":"22036","inReplyTo":"alpine.DEB.2.00.0912281745540.5582@cone.home.martin.st","subject":"Re: [PATCH] Allow git to use any HTTP authentication method.","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-12-28T15:53:46Z","receivedAt":"2009-12-28T15:53:46Z","isPatch":true,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Martin Storsj? <martin@martin.st> wrote:\n> Initially when I added support for this, curl sessions weren't reused, so \n> every single request had to be duplicated if authentication was used, \n> adding quite a bit of overhead.\n> \n> Now that sessions are reused properly, I tend to agree that this should be \n> enabled automatically.\n\nOh, that makes sense, thanks for the explanation.\n \n> Should I send in a new patch that removes the http.authAny option and \n> always enables this, or send a rewritten version of the patch that already \n> is in 'next'?\n\nI'm not Junio, but I would suggest sending in a new patch series,\nand asking Junio politely to revert the one that is currently in\nnext before merging in the new series.\n\nIf we really are killing http.authAny before it hits master, there\nis no reason for it to appear in the final project history.\n\n-- \nShawn.\n"},{"id":"130406","messageId":"be6fef0d0912280915k1320110o6a361a0950aa60f6@mail.gmail.com","threadId":"22036","inReplyTo":"20091228155346.GB2252@spearce.org","subject":"Re: [PATCH] Allow git to use any HTTP authentication method.","fromName":"Tay Ray Chuan","fromEmail":"rctay89@gmail.com","sentAt":"2009-12-28T17:15:48Z","receivedAt":"2009-12-28T17:15:48Z","isPatch":true,"sender":{"key":"rctay89@gmail.com","avatar":"https://avatars.githubusercontent.com/u/61553?v=4"},"body":"Hi,\n\nOn Mon, Dec 28, 2009 at 11:53 PM, Shawn O. Pearce <spearce@spearce.org> wrote:\n> Martin Storsj? <martin@martin.st> wrote:\n>> Should I send in a new patch that removes the http.authAny option and\n>> always enables this, or send a rewritten version of the patch that already\n>> is in 'next'?\n>\n> I'm not Junio, but I would suggest sending in a new patch series,\n> and asking Junio politely to revert the one that is currently in\n> next before merging in the new series.\n>\n> If we really are killing http.authAny before it hits master, there\n> is no reason for it to appear in the final project history.\n\nhmm, a few days back Junio (added to Cc list) sent out an email\nregarding branch shuffling and dropping topics from 'next'. Junio,\ncould we piggyback on this?\n\n-- \nCheers,\nRay Chuan\n"},{"id":"130407","messageId":"7vd41zrn4n.fsf@alter.siamese.dyndns.org","threadId":"22036","inReplyTo":"be6fef0d0912280915k1320110o6a361a0950aa60f6@mail.gmail.com","subject":"Re: [PATCH] Allow git to use any HTTP authentication method.","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2009-12-28T18:04:24Z","receivedAt":"2009-12-28T18:04:24Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Tay Ray Chuan <rctay89@gmail.com> writes:\n\n> On Mon, Dec 28, 2009 at 11:53 PM, Shawn O. Pearce <spearce@spearce.org> wrote:\n>> Martin Storsj? <martin@martin.st> wrote:\n>>> Should I send in a new patch that removes the http.authAny option and\n>>> always enables this, or send a rewritten version of the patch that already\n>>> is in 'next'?\n>>\n>> I'm not Junio, but I would suggest sending in a new patch series,\n>> and asking Junio politely to revert the one that is currently in\n>> next before merging in the new series.\n>>\n>> If we really are killing http.authAny before it hits master, there\n>> is no reason for it to appear in the final project history.\n>\n> hmm, a few days back Junio (added to Cc list) sent out an email\n> regarding branch shuffling and dropping topics from 'next'. Junio,\n> could we piggyback on this?\n\nIf people want to go that way that is fine by me, but unlike the ones that\nare _ejected_ from next without trace, if we are going to have the primary\nfeature the patch introduces and changing only a minor detail of external\ninterface, I don't think we gain much by hinding that story from the\nhistory, especially for something that has been cooking in 'next'.\n\nA separate follow-up commit would be more honest about the feature's\nhistory.  Also a follow-up patch to remove conditionals is much easier to\nreview than a resend of a rewritten patch, especially when the original\nwas reviewed adequately for its primary codepath to implement the feature.\n\nWould it be just a matter of queueing something like this on top of\nb8ac923 (Add an option for using any HTTP authentication scheme, not only\nbasic, 2009-11-27)?\n\n-- >8 -- \nFrom: \"Shawn O. Pearce\" <spearce@spearce.org>,\nSubject: Remove http.authAny\n\nBack when the feature to use different HTTP authentication methods was\noriginally written, it needed an extra HTTP request for everything when\nthe feature was in effect, because we didn't reuse curl sessions.\n\nHowever, b8ac923 (Add an option for using any HTTP authentication scheme,\nnot only basic, 2009-11-27) builds on top of an updated codebase that does\nreuse curl sessions; there is no need to manually avoid the extra overhead\nby making this configurable anymore.\n\n---\n Documentation/config.txt |    7 -------\n http.c                   |   17 +----------------\n 2 files changed, 1 insertions(+), 23 deletions(-)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex a54ede3..b77d66d 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -1158,13 +1158,6 @@ http.noEPSV::\n \tsupport EPSV mode. Can be overridden by the 'GIT_CURL_FTP_NO_EPSV'\n \tenvironment variable. Default is false (curl will use EPSV).\n \n-http.authAny::\n-\tAllow any HTTP authentication method, not only basic. Enabling\n-\tthis lowers the performance slightly, by having to do requests\n-\twithout any authentication to discover the authentication method\n-\tto use. Can be overridden by the 'GIT_HTTP_AUTH_ANY'\n-\tenvironment variable. Default is false.\n-\n i18n.commitEncoding::\n \tCharacter encoding the commit messages are stored in; git itself\n \tdoes not care per se, but this information is necessary e.g. when\ndiff --git a/http.c b/http.c\nindex aeb69b3..01e0fdc 100644\n--- a/http.c\n+++ b/http.c\n@@ -40,9 +40,6 @@ static long curl_low_speed_time = -1;\n static int curl_ftp_no_epsv;\n static const char *curl_http_proxy;\n static char *user_name, *user_pass;\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n-static int curl_http_auth_any = 0;\n-#endif\n \n #if LIBCURL_VERSION_NUM >= 0x071700\n /* Use CURLOPT_KEYPASSWD as is */\n@@ -197,12 +194,6 @@ static int http_options(const char *var, const char *value, void *cb)\n \t\t\thttp_post_buffer = LARGE_PACKET_MAX;\n \t\treturn 0;\n \t}\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n-\tif (!strcmp(\"http.authany\", var)) {\n-\t\tcurl_http_auth_any = git_config_bool(var, value);\n-\t\treturn 0;\n-\t}\n-#endif\n \n \t/* Fall back on the default ones */\n \treturn git_default_config(var, value, cb);\n@@ -254,8 +245,7 @@ static CURL *get_curl_handle(void)\n \tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n #endif\n #ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n-\tif (curl_http_auth_any)\n-\t\tcurl_easy_setopt(result, CURLOPT_HTTPAUTH, CURLAUTH_ANY);\n+\tcurl_easy_setopt(result, CURLOPT_HTTPAUTH, CURLAUTH_ANY);\n #endif\n \n \tinit_curl_http_auth(result);\n@@ -408,11 +398,6 @@ void http_init(struct remote *remote)\n \tif (getenv(\"GIT_CURL_FTP_NO_EPSV\"))\n \t\tcurl_ftp_no_epsv = 1;\n \n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n-\tif (getenv(\"GIT_HTTP_AUTH_ANY\"))\n-\t\tcurl_http_auth_any = 1;\n-#endif\n-\n \tif (remote && remote->url && remote->url[0]) {\n \t\thttp_auth_init(remote->url[0]);\n \t\tif (!ssl_cert_password_required &&\n"},{"id":"130408","messageId":"alpine.DEB.2.00.0912282008320.5582@cone.home.martin.st","threadId":"22036","inReplyTo":"7vd41zrn4n.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH] Allow git to use any HTTP authentication method.","fromName":"Martin Storsjö","fromEmail":"martin@martin.st","sentAt":"2009-12-28T18:10:12Z","receivedAt":"2009-12-28T18:10:12Z","isPatch":true,"sender":{"key":"martin@martin.st","avatar":"https://avatars.githubusercontent.com/u/69727?v=4"},"body":"On Mon, 28 Dec 2009, Junio C Hamano wrote:\n\n> Would it be just a matter of queueing something like this on top of\n> b8ac923 (Add an option for using any HTTP authentication scheme, not only\n> basic, 2009-11-27)?\n\nLooks good to me:\n\nAcked-by: Martin Storsjo <martin@martin.st>\n\n// Martin\n"},{"id":"130409","messageId":"20091228181501.GF2252@spearce.org","threadId":"22036","inReplyTo":"7vd41zrn4n.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH] Allow git to use any HTTP authentication method.","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-12-28T18:15:01Z","receivedAt":"2009-12-28T18:15:01Z","isPatch":true,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Junio C Hamano <gitster@pobox.com> wrote:\n> -- >8 -- \n> From: \"Shawn O. Pearce\" <spearce@spearce.org>,\n> Subject: Remove http.authAny\n\nAck.\n\nBut I'm not sure I should be the author, you did all of the legwork\nand therefore should get credit for it.  :-)\n\n-- \nShawn.\n"}]}