{"thread":{"id":"30779","subject":"[PATCH/RFC] Add 'git credential' plumbing command","startedAt":"2012-06-12T14:24:04Z","lastAt":"2012-06-12T14:36:03Z","messageCount":4,"participants":["javier.roucher-iglesias@ensimag.imag.fr","Matthieu Moy","Jeff King"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"193440","messageId":"1339511044-29977-1-git-send-email-Javier.Roucher-Iglesias@ensimag.imag.fr","threadId":"30779","inReplyTo":null,"subject":"[PATCH/RFC] Add 'git credential' plumbing command","fromName":"","fromEmail":"javier.roucher-iglesias@ensimag.imag.fr","sentAt":"2012-06-12T14:24:04Z","receivedAt":"2012-06-12T14:24:04Z","isPatch":true,"sender":{"key":"javier.roucher-iglesias@ensimag.imag.fr","avatar":null},"body":"From: Javier Roucher <jroucher@gmail.com>\n\nTest is comming\nwe are working to added soon.\n\n---\n .gitignore                       |  1 +\n Documentation/git-credential.txt | 74 ++++++++++++++++++++++++++++++++++++++++\n Makefile                         |  1 +\n builtin.h                        |  1 +\n builtin/credential.c             | 40 ++++++++++++++++++++++\n git.c                            |  1 +\n 6 files changed, 118 insertions(+)\n create mode 100644 Documentation/git-credential.txt\n create mode 100644 builtin/credential.c\n\ndiff --git a/.gitignore b/.gitignore\nindex bf66648..7d1d86e 100644\n--- a/.gitignore\n+++ b/.gitignore\n@@ -31,6 +31,7 @@\n /git-commit-tree\n /git-config\n /git-count-objects\n+/git-credential\n /git-credential-cache\n /git-credential-cache--daemon\n /git-credential-store\ndiff --git a/Documentation/git-credential.txt b/Documentation/git-credential.txt\nnew file mode 100644\nindex 0000000..fa05aad\n--- /dev/null\n+++ b/Documentation/git-credential.txt\n@@ -0,0 +1,74 @@\n+git-credential(7)\n+=================\n+\n+NAME\n+----\n+git-credential - Provide and store user credentials.\n+\n+SYNOPSIS\n+--------\n+------------------\n+git credential <fill|approve|reject>\n+\n+------------------\n+\n+DESCRIPTION\n+-----------\n+\n+Git-credential permits to the user of the script to save:\n+username, password, host, path and protocol. When the user of script\n+invoke git-credential, the script can ask for a password, using the command\n+'git credential fill'.\n+Taking data from the standard input, the program treats each line as a\n+separate data item, and the end of series of data item is signalled by a \n+blank line.\n+\n+\t\tusername=admin\\n \n+\t\tprotocol=[http|https]\\n\n+\t\thost=localhost\\n\n+\t\tpath=/dir\\n\\n\n+\n+-If git-credential system has the password already stored\n+git-credential will answer with by STDOUT:\n+\t\n+\t\tusername=admin\n+\t\tpassword=*****\n+\n+-If it is not stored, the user will be prompt for a password:\n+\t\t\n+\t\t> Password for '[http|https]admin@localhost':\n+\n+\n+Then if the password is correct, (note: it's not git credential that\n+decides if the password is correct or not. That part is done by the \n+external system) it can be stored using command 'git crendential approve' \n+by providing the structure, by STDIN.\n+\n+\t\tusername=admin\n+\t\tpassword=*****\n+\t\tprotocol=[http|https]\n+\t\thost=localhost\n+\t\tpath=/dir\n+\n+If the password is refused, it can be deleted using command\n+'git credential reject' by providing the same structure.\n+\n+\n+REQUESTING CREDENTIALS\n+----------------------\n+\n+1. The 'git credential fill' makes the structure,\n+with this structure it will be able to save your\n+credentials, and if the credential is already stored,\n+it will fill the password.\n+\n+\t\tusername=foo\n+\t\tpassword=****\n+\t\tprotocol=[http|https]\n+\t\tlocalhost=url\n+\t\tpath=/direction\n+\n+2. Then 'git credential approve' to store them.\n+\n+3. Otherwise, if the credential is not correct you can do\n+  'git credential reject' to delete the credential.\ndiff --git a/Makefile b/Makefile\nindex 4592f1f..3f53da8 100644\n--- a/Makefile\n+++ b/Makefile\n@@ -827,6 +827,7 @@ BUILTIN_OBJS += builtin/commit-tree.o\n BUILTIN_OBJS += builtin/commit.o\n BUILTIN_OBJS += builtin/config.o\n BUILTIN_OBJS += builtin/count-objects.o\n+BUILTIN_OBJS += builtin/credential.o\n BUILTIN_OBJS += builtin/describe.o\n BUILTIN_OBJS += builtin/diff-files.o\n BUILTIN_OBJS += builtin/diff-index.o\ndiff --git a/builtin.h b/builtin.h\nindex 338f540..48feddc 100644\n--- a/builtin.h\n+++ b/builtin.h\n@@ -66,6 +66,7 @@ extern int cmd_commit(int argc, const char **argv, const char *prefix);\n extern int cmd_commit_tree(int argc, const char **argv, const char *prefix);\n extern int cmd_config(int argc, const char **argv, const char *prefix);\n extern int cmd_count_objects(int argc, const char **argv, const char *prefix);\n+extern int cmd_credential(int argc, const char **argv, const char *prefix);\n extern int cmd_describe(int argc, const char **argv, const char *prefix);\n extern int cmd_diff_files(int argc, const char **argv, const char *prefix);\n extern int cmd_diff_index(int argc, const char **argv, const char *prefix);\ndiff --git a/builtin/credential.c b/builtin/credential.c\nnew file mode 100644\nindex 0000000..c8dcfbb\n--- /dev/null\n+++ b/builtin/credential.c\n@@ -0,0 +1,40 @@\n+#include <stdio.h>\n+#include \"cache.h\"\n+#include \"credential.h\"\n+#include \"string-list.h\"\n+\n+static const char usage_msg[] =\n+\"credential <fill|approve|reject>\";\n+\n+void cmd_credential (int argc, char **argv, const char *prefix) {\n+\tconst char *op;\n+\tstruct credential c = CREDENTIAL_INIT;\n+\tint i;\n+\n+\top = argv[1];\n+\tif (!op)\n+\t\tusage(usage_msg);\n+\n+\tif (credential_read(&c, stdin) < 0)\n+\t\tdie(\"unable to read credential from stdin\");\n+\n+\tif (!strcmp(op, \"fill\")) {\n+\t\tcredential_fill(&c);\n+\t\tif (c.username)\n+\t\t\tprintf(\"username=%s\\n\", c.username);\n+\t\tif (c.password)\n+\t\t\tprintf(\"password=%s\\n\", c.password);\n+\t\tif (c.protocol)\n+\t\t\tprintf(\"protocol=%s\\n\", c.protocol);\n+\t\tif (c.host)\n+\t\t\tprintf(\"host=%s\\n\", c.host);\n+\t\tif (c.path)\n+\t\t\tprintf(\"path=%s\\n\", c.path);\n+\t} else if (!strcmp(op, \"approve\")) {\n+\t\tcredential_approve(&c);\n+\t} else if (!strcmp(op, \"reject\")) {\n+\t\tcredential_reject(&c);\n+\t} else {\n+\t\tusage(usage_msg);\n+\t}\n+}\ndiff --git a/git.c b/git.c\nindex d232de9..660c926 100644\n--- a/git.c\n+++ b/git.c\n@@ -353,6 +353,7 @@ static void handle_internal_command(int argc, const char **argv)\n \t\t{ \"commit-tree\", cmd_commit_tree, RUN_SETUP },\n \t\t{ \"config\", cmd_config, RUN_SETUP_GENTLY },\n \t\t{ \"count-objects\", cmd_count_objects, RUN_SETUP },\n+\t\t{ \"credential\", cmd_credential, RUN_SETUP_GENTLY },\n \t\t{ \"describe\", cmd_describe, RUN_SETUP },\n \t\t{ \"diff\", cmd_diff },\n \t\t{ \"diff-files\", cmd_diff_files, RUN_SETUP | NEED_WORK_TREE },\n-- \n1.7.10.2.573.ged8bfa6\n"},{"id":"193442","messageId":"vpq3960r48q.fsf@bauges.imag.fr","threadId":"30779","inReplyTo":"1339511044-29977-1-git-send-email-Javier.Roucher-Iglesias@ensimag.imag.fr","subject":"Re: [PATCH/RFC] Add 'git credential' plumbing command","fromName":"Matthieu Moy","fromEmail":"matthieu.moy@grenoble-inp.fr","sentAt":"2012-06-12T14:31:33Z","receivedAt":"2012-06-12T14:31:33Z","isPatch":true,"sender":{"key":"matthieu.moy@grenoble-inp.fr","avatar":"https://gravatar.com/avatar/72c8a2705971a25dfaff23cece15130d405685845d911aedd5667ace277f3fc5?d=mp&s=160"},"body":"Javier.Roucher-Iglesias@ensimag.imag.fr writes:\n\n> +git credential <fill|approve|reject>\n\nYou didn't take Jeff's suggestions into account:\n\nhttp://thread.gmane.org/gmane.comp.version-control.git/199552/focus=199591\n\nIt's clearly too late to implement the whole suggested API, but I do\nlike the suggestion of allowing either a URL as argument or individual\nfields on stdin, or both combined, by using the --stdin argument.\n\nTo allow further patches to implement this without breaking backward\ncompatibility, your implementation could require the use of --stdin on\nthe command-line.\n\n-- \nMatthieu Moy\nhttp://www-verimag.imag.fr/~moy/\n"},{"id":"193443","messageId":"20120612143411.GA7524@sigill.intra.peff.net","threadId":"30779","inReplyTo":"vpq3960r48q.fsf@bauges.imag.fr","subject":"Re: [PATCH/RFC] Add 'git credential' plumbing command","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2012-06-12T14:34:11Z","receivedAt":"2012-06-12T14:34:11Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Tue, Jun 12, 2012 at 04:31:33PM +0200, Matthieu Moy wrote:\n\n> Javier.Roucher-Iglesias@ensimag.imag.fr writes:\n> \n> > +git credential <fill|approve|reject>\n> \n> You didn't take Jeff's suggestions into account:\n> \n> http://thread.gmane.org/gmane.comp.version-control.git/199552/focus=199591\n> \n> It's clearly too late to implement the whole suggested API, but I do\n> like the suggestion of allowing either a URL as argument or individual\n> fields on stdin, or both combined, by using the --stdin argument.\n> \n> To allow further patches to implement this without breaking backward\n> compatibility, your implementation could require the use of --stdin on\n> the command-line.\n\nActually, after further discussion, I think that --stdin is unnecessary.\nIf you are providing a URL, you should always provide it via stdin\nbecause of the password-disclosure issue. It's tempting to provide a\ncommand-line alternative because it's easier, but I think it would just\nencourage lazy developers to do the wrong thing.\n\nI do still think respecting \"url=\" when reading a credential makes\nsense, but that is easy to add later.\n\n-Peff\n"},{"id":"193444","messageId":"vpqy5nsppgs.fsf@bauges.imag.fr","threadId":"30779","inReplyTo":"20120612143411.GA7524@sigill.intra.peff.net","subject":"Re: [PATCH/RFC] Add 'git credential' plumbing command","fromName":"Matthieu Moy","fromEmail":"matthieu.moy@grenoble-inp.fr","sentAt":"2012-06-12T14:36:03Z","receivedAt":"2012-06-12T14:36:03Z","isPatch":true,"sender":{"key":"matthieu.moy@grenoble-inp.fr","avatar":"https://gravatar.com/avatar/72c8a2705971a25dfaff23cece15130d405685845d911aedd5667ace277f3fc5?d=mp&s=160"},"body":"Jeff King <peff@peff.net> writes:\n\n> On Tue, Jun 12, 2012 at 04:31:33PM +0200, Matthieu Moy wrote:\n>\n>> Javier.Roucher-Iglesias@ensimag.imag.fr writes:\n>> \n>> > +git credential <fill|approve|reject>\n>> \n>> You didn't take Jeff's suggestions into account:\n>> \n>> http://thread.gmane.org/gmane.comp.version-control.git/199552/focus=199591\n>> \n>> It's clearly too late to implement the whole suggested API, but I do\n>> like the suggestion of allowing either a URL as argument or individual\n>> fields on stdin, or both combined, by using the --stdin argument.\n>> \n>> To allow further patches to implement this without breaking backward\n>> compatibility, your implementation could require the use of --stdin on\n>> the command-line.\n>\n> Actually, after further discussion, I think that --stdin is unnecessary.\n> If you are providing a URL, you should always provide it via stdin\n> because of the password-disclosure issue. It's tempting to provide a\n> command-line alternative because it's easier, but I think it would just\n> encourage lazy developers to do the wrong thing.\n\nOK, that makes sense.\n\n> I do still think respecting \"url=\" when reading a credential makes\n> sense, but that is easy to add later.\n\nOK, so in short: Javier, you can ignore my comment.\n\n-- \nMatthieu Moy\nhttp://www-verimag.imag.fr/~moy/\n"}]}