{"thread":{"id":"51042","subject":"GIT/SSH_ASKPASS used for username input in https:// URLs","startedAt":"2019-05-06T14:18:31Z","lastAt":"2019-05-07T07:36:11Z","messageCount":2,"participants":["Andreas Krey","Jeff King"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"374945","messageId":"20190506134718.GA12803@inner.h.apk.li","threadId":"51042","inReplyTo":null,"subject":"GIT/SSH_ASKPASS used for username input in https:// URLs","fromName":"Andreas Krey","fromEmail":"a.krey@gmx.de","sentAt":"2019-05-06T13:47:18Z","receivedAt":"2019-05-06T14:18:31Z","isPatch":false,"sender":{"key":"a.krey@gmx.de","avatar":"https://avatars.githubusercontent.com/u/37810?v=4"},"body":"Hi everyone,\n\nthere is an interesting wart around prompt.c -\nPROMPT_ECHO isn't used in invoking an external helper program.\n\nThus, if I clone something on https (which requires auth for that),\nand have SSH_ASKPASS set, I will get two GUI *password* prompts,\neven though the first one will indicate in the title that it *is*\nasking for the username.\n\nBut basically, given the trivial protocol of SSH_ASKPASS, there\ndoesn't seem to be any way to properly fix this without support\nfrom any desktop environment that sets SSH_ASKPASS. :-(\n\nThe best I can currently tell my users is to use the\n   [credentials \"https:/...\"]\nconfiguration to fix the username.\n\nBut if we can't fix this, maybe we can at least point this out in the docs?\n\n- Andreas\n\n-- \n\"Totally trivial. Famous last words.\"\nFrom: Linus Torvalds <torvalds@*.org>\nDate: Fri, 22 Jan 2010 07:29:21 -0800\n"},{"id":"374994","messageId":"20190507073608.GE28060@sigill.intra.peff.net","threadId":"51042","inReplyTo":"20190506134718.GA12803@inner.h.apk.li","subject":"Re: GIT/SSH_ASKPASS used for username input in https:// URLs","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2019-05-07T07:36:08Z","receivedAt":"2019-05-07T07:36:11Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Mon, May 06, 2019 at 03:47:18PM +0200, Andreas Krey wrote:\n\n> there is an interesting wart around prompt.c -\n> PROMPT_ECHO isn't used in invoking an external helper program.\n> \n> Thus, if I clone something on https (which requires auth for that),\n> and have SSH_ASKPASS set, I will get two GUI *password* prompts,\n> even though the first one will indicate in the title that it *is*\n> asking for the username.\n> \n> But basically, given the trivial protocol of SSH_ASKPASS, there\n> doesn't seem to be any way to properly fix this without support\n> from any desktop environment that sets SSH_ASKPASS. :-(\n\nYep. If you haven't seen it, there's more discussion in this recent\nthread:\n\n  https://public-inbox.org/git/20190429234028.GA24069@sigill.intra.peff.net/\n\n> The best I can currently tell my users is to use the\n>    [credentials \"https:/...\"]\n> configuration to fix the username.\n\nYes, that works. Or a credential helper could prompt with a better\ninterface (but AFAIK, the only one written that does so is the Windows\none).\n\n> But if we can't fix this, maybe we can at least point this out in the\n> docs?\n\nSounds like a good suggestion. Where would you look for it? In the\ndescription of GIT_ASKPASS / core.askpass?\n\n-Peff\n"}]}