{"thread":{"id":"28778","subject":"Credentials and the Secrets API...","startedAt":"2011-10-27T16:05:03Z","lastAt":"2013-02-21T19:27:47Z","messageCount":7,"participants":["John Szakmeister","Jeff King","Ted Zlatanov"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"178356","messageId":"CAEBDL5Udooim_3Za76Q1Rt_aGXtsSv76nxRegGWRBE=WJQzfZA@mail.gmail.com","threadId":"28778","inReplyTo":null,"subject":"Credentials and the Secrets API...","fromName":"John Szakmeister","fromEmail":"john@szakmeister.net","sentAt":"2011-10-27T16:05:03Z","receivedAt":"2011-10-27T16:05:03Z","isPatch":false,"sender":{"key":"john@szakmeister.net","avatar":"https://avatars.githubusercontent.com/u/448087?v=4"},"body":"Just wanted to keep folks in the loop.  It turns out that the Secrets\nAPI is still to young.  I asked about the format to store credentials\nin (as far as attributes), and got a response from a KDE developer\nthat says it's still to young on their front.  They hope to have\nsupport in the next release of KDE.  But there's still the issue of\nwhat attributes to use.\n\nWith that information, I went ahead and created a\ngnome-credential-keyring that uses Gnome's Keyring facility.  I still\nneed to do a few more things (mainly run it against Jeff's tests), but\nit's generally working.  Just wanted to keep folks in the loop.\nHopefully, I can get patches out this weekend.\n\nJeff: it would be really excellent to break out the various pieces.  I\nthink it would also be better to split the asking for passwords from\nthe storing of passwords.\n\n-John\n"},{"id":"178366","messageId":"20111027174807.GD1967@sigill.intra.peff.net","threadId":"28778","inReplyTo":"CAEBDL5Udooim_3Za76Q1Rt_aGXtsSv76nxRegGWRBE=WJQzfZA@mail.gmail.com","subject":"Re: Credentials and the Secrets API...","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2011-10-27T17:48:07Z","receivedAt":"2011-10-27T17:48:07Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Oct 27, 2011 at 12:05:03PM -0400, John Szakmeister wrote:\n\n> Just wanted to keep folks in the loop.  It turns out that the Secrets\n> API is still to young.  I asked about the format to store credentials\n> in (as far as attributes), and got a response from a KDE developer\n> that says it's still to young on their front.  They hope to have\n> support in the next release of KDE.  But there's still the issue of\n> what attributes to use.\n\nThanks for looking into this. That explains why I had such trouble\nfinding good documentation on it.\n\n> With that information, I went ahead and created a\n> gnome-credential-keyring that uses Gnome's Keyring facility.  I still\n> need to do a few more things (mainly run it against Jeff's tests), but\n> it's generally working.  Just wanted to keep folks in the loop.\n> Hopefully, I can get patches out this weekend.\n\nGreat, I'm looking forward to reading it.\n\n> Jeff: it would be really excellent to break out the various pieces.  I\n> think it would also be better to split the asking for passwords from\n> the storing of passwords.\n\nThat's my current plan. I just need to stop dragging my feet on\nre-rolling the series.\n\n-Peff\n"},{"id":"178614","messageId":"CAEBDL5XOnsq1zBRq+f1zKJqQvxJjRPywCRbPKn77x9Yaa4QVkA@mail.gmail.com","threadId":"28778","inReplyTo":"20111027174807.GD1967@sigill.intra.peff.net","subject":"Re: Credentials and the Secrets API...","fromName":"John Szakmeister","fromEmail":"john@szakmeister.net","sentAt":"2011-11-01T06:39:07Z","receivedAt":"2011-11-01T06:39:07Z","isPatch":false,"sender":{"key":"john@szakmeister.net","avatar":"https://avatars.githubusercontent.com/u/448087?v=4"},"body":"On Thu, Oct 27, 2011 at 1:48 PM, Jeff King <peff@peff.net> wrote:\n> On Thu, Oct 27, 2011 at 12:05:03PM -0400, John Szakmeister wrote:\n[snip]\n>> With that information, I went ahead and created a\n>> gnome-credential-keyring that uses Gnome's Keyring facility.  I still\n>> need to do a few more things (mainly run it against Jeff's tests), but\n>> it's generally working.  Just wanted to keep folks in the loop.\n>> Hopefully, I can get patches out this weekend.\n>\n> Great, I'm looking forward to reading it.\n\nI've pushed up the work I've done to:\n   <https://github.com/jszakmeister/git-credential-keyring>\n\nThere's not much to it.  It also doesn't handle certs and that sort of\nthing.  I think we need to figure out which protocols need to be\nhandled differently so that we can use the appropriate api for the\nkeyring-like api. :-)\n\nI also chose this way instead of a patch to git, because it appears\nyour work is no longer in pu (I must have missed the fact that it was\nremoved).  Once your work makes it way back in, I can look into\ngetting it into the contrib area, if that's desired.\n\n>> Jeff: it would be really excellent to break out the various pieces.  I\n>> think it would also be better to split the asking for passwords from\n>> the storing of passwords.\n>\n> That's my current plan. I just need to stop dragging my feet on\n> re-rolling the series.\n\nSounds good!  I'll be happy to update when you do re-roll it.  The\ntest you sent out was very helpful, BTW.  I do think the test cases\nwith no context are a bit broken though.  It doesn't seem right to ask\nthe storage backend to retrieve a password without any context at all,\nIMHO.  My implementation doesn't pass those two tests.  It does pass\nthe rest of them though.\n\n-John\n"},{"id":"208921","messageId":"87halochci.fsf@lifelogs.com","threadId":"28778","inReplyTo":"CAEBDL5Udooim_3Za76Q1Rt_aGXtsSv76nxRegGWRBE=WJQzfZA@mail.gmail.com","subject":"Re: Credentials and the Secrets API...","fromName":"Ted Zlatanov","fromEmail":"tzz@lifelogs.com","sentAt":"2013-02-07T14:46:05Z","receivedAt":"2013-02-07T14:46:05Z","isPatch":false,"sender":{"key":"tzz@lifelogs.com","avatar":"https://avatars.githubusercontent.com/u/67764?v=4"},"body":"On Thu, 27 Oct 2011 12:05:03 -0400 John Szakmeister <john@szakmeister.net> wrote: \n\nJS> Just wanted to keep folks in the loop.  It turns out that the Secrets\nJS> API is still to young.  I asked about the format to store credentials\nJS> in (as far as attributes), and got a response from a KDE developer\nJS> that says it's still to young on their front.  They hope to have\nJS> support in the next release of KDE.  But there's still the issue of\nJS> what attributes to use.\n\nJS> With that information, I went ahead and created a\nJS> gnome-credential-keyring that uses Gnome's Keyring facility.  I still\nJS> need to do a few more things (mainly run it against Jeff's tests), but\nJS> it's generally working.  Just wanted to keep folks in the loop.\nJS> Hopefully, I can get patches out this weekend.\n\nDo you think the Secrets API has matured enough?  KDE has had a new\nrelease since your post...\n\nThanks\nTed\n"},{"id":"209076","messageId":"CAEBDL5VQxhnL+wdkf_5=MmG4ptBr4TFyyAvbMWxRom9SRxJ6Lg@mail.gmail.com","threadId":"28778","inReplyTo":"87halochci.fsf@lifelogs.com","subject":"Re: Credentials and the Secrets API...","fromName":"John Szakmeister","fromEmail":"john@szakmeister.net","sentAt":"2013-02-09T10:58:47Z","receivedAt":"2013-02-09T10:58:47Z","isPatch":false,"sender":{"key":"john@szakmeister.net","avatar":"https://avatars.githubusercontent.com/u/448087?v=4"},"body":"On Thu, Feb 7, 2013 at 9:46 AM, Ted Zlatanov <tzz@lifelogs.com> wrote:\n> On Thu, 27 Oct 2011 12:05:03 -0400 John Szakmeister <john@szakmeister.net> wrote:\n>\n> JS> Just wanted to keep folks in the loop.  It turns out that the Secrets\n> JS> API is still to young.  I asked about the format to store credentials\n> JS> in (as far as attributes), and got a response from a KDE developer\n> JS> that says it's still to young on their front.  They hope to have\n> JS> support in the next release of KDE.  But there's still the issue of\n> JS> what attributes to use.\n>\n> JS> With that information, I went ahead and created a\n> JS> gnome-credential-keyring that uses Gnome's Keyring facility.  I still\n> JS> need to do a few more things (mainly run it against Jeff's tests), but\n> JS> it's generally working.  Just wanted to keep folks in the loop.\n> JS> Hopefully, I can get patches out this weekend.\n>\n> Do you think the Secrets API has matured enough?  KDE has had a new\n> release since your post...\n\nYes, I think it has.  Several other applications appear to be using\nit, including some things considered \"core\" in Fedora--which is a good\nsign.\n\n-John\n"},{"id":"209913","messageId":"87k3q2yl4y.fsf@lifelogs.com","threadId":"28778","inReplyTo":"CAEBDL5VQxhnL+wdkf_5=MmG4ptBr4TFyyAvbMWxRom9SRxJ6Lg@mail.gmail.com","subject":"Re: Credentials and the Secrets API...","fromName":"Ted Zlatanov","fromEmail":"tzz@lifelogs.com","sentAt":"2013-02-20T17:01:49Z","receivedAt":"2013-02-20T17:01:49Z","isPatch":false,"sender":{"key":"tzz@lifelogs.com","avatar":"https://avatars.githubusercontent.com/u/67764?v=4"},"body":"On Sat, 9 Feb 2013 05:58:47 -0500 John Szakmeister <john@szakmeister.net> wrote: \n\nJS> On Thu, Feb 7, 2013 at 9:46 AM, Ted Zlatanov <tzz@lifelogs.com> wrote:\n>> On Thu, 27 Oct 2011 12:05:03 -0400 John Szakmeister <john@szakmeister.net> wrote:\n>> \nJS> Just wanted to keep folks in the loop.  It turns out that the Secrets\nJS> API is still to young.  I asked about the format to store credentials\nJS> in (as far as attributes), and got a response from a KDE developer\nJS> that says it's still to young on their front.  They hope to have\nJS> support in the next release of KDE.  But there's still the issue of\nJS> what attributes to use.\n\n>> Do you think the Secrets API has matured enough?  KDE has had a new\n>> release since your post...\n\nJS> Yes, I think it has.  Several other applications appear to be using\nJS> it, including some things considered \"core\" in Fedora--which is a good\nJS> sign.\n\nWonderful.  Do you still have interest in working on this credential?\n\nTed\n"},{"id":"209986","messageId":"CAEBDL5UkCLwqn6JBkfu_sfWifh-7K9v6GfSAhhRzx7WaUaRovA@mail.gmail.com","threadId":"28778","inReplyTo":"87k3q2yl4y.fsf@lifelogs.com","subject":"Re: Credentials and the Secrets API...","fromName":"John Szakmeister","fromEmail":"john@szakmeister.net","sentAt":"2013-02-21T19:27:47Z","receivedAt":"2013-02-21T19:27:47Z","isPatch":false,"sender":{"key":"john@szakmeister.net","avatar":"https://avatars.githubusercontent.com/u/448087?v=4"},"body":"On Wed, Feb 20, 2013 at 12:01 PM, Ted Zlatanov <tzz@lifelogs.com> wrote:\n> On Sat, 9 Feb 2013 05:58:47 -0500 John Szakmeister <john@szakmeister.net> wrote:\n[snip]\n>\n> JS> Yes, I think it has.  Several other applications appear to be using\n> JS> it, including some things considered \"core\" in Fedora--which is a good\n> JS> sign.\n>\n> Wonderful.  Do you still have interest in working on this credential?\n\nI do, but I'm a bit short on time right now.  So if you or someone\nelse wants to pick up and run with it, please feel free.  If I get\nsome cycles over the next couple of months, I'll give it a go though.\n\n-John\n"}]}