{"thread":{"id":"55298","subject":"[PATCH v3 2/2] http: drop the check for an empty proxy password before approving","startedAt":"2021-03-12T02:41:15Z","lastAt":"2021-03-12T21:05:33Z","messageCount":4,"participants":["John Szakmeister","brian m. carlson"],"isPatch":true,"patchVersion":3,"patchTotal":2},"messages":[{"id":"418923","messageId":"20210312024027.33418-3-john@szakmeister.net","threadId":"55298","inReplyTo":"20210312024027.33418-1-john@szakmeister.net","subject":"[PATCH v3 2/2] http: drop the check for an empty proxy password before approving","fromName":"John Szakmeister","fromEmail":"john@szakmeister.net","sentAt":"2021-03-12T02:40:27Z","receivedAt":"2021-03-12T02:41:15Z","isPatch":true,"sender":{"key":"john@szakmeister.net","avatar":"https://avatars.githubusercontent.com/u/448087?v=4"},"body":"credential_approve() already checks for a non-empty password before\nsaving, so there's no need to do the extra check here.\n\nSigned-off-by: John Szakmeister <john@szakmeister.net>\n---\n http.c | 3 +--\n 1 file changed, 1 insertion(+), 2 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 60d01c6e83..3aeabf0947 100644\n--- a/http.c\n+++ b/http.c\n@@ -1635,8 +1635,7 @@ static int handle_curl_result(struct slot_results *results)\n \n \tif (results->curl_result == CURLE_OK) {\n \t\tcredential_approve(&http_auth);\n-\t\tif (proxy_auth.password)\n-\t\t\tcredential_approve(&proxy_auth);\n+\t\tcredential_approve(&proxy_auth);\n \t\tcredential_approve(&cert_auth);\n \t\treturn HTTP_OK;\n \t} else if (results->curl_result == CURLE_SSL_CERTPROBLEM) {\n-- \n2.30.1\n\n"},{"id":"418924","messageId":"20210312024027.33418-1-john@szakmeister.net","threadId":"55298","inReplyTo":null,"subject":"[PATCH v3 0/2] http: store credential when PKI auth is used","fromName":"John Szakmeister","fromEmail":"john@szakmeister.net","sentAt":"2021-03-12T02:40:25Z","receivedAt":"2021-03-12T02:41:15Z","isPatch":true,"sender":{"key":"john@szakmeister.net","avatar":"https://avatars.githubusercontent.com/u/448087?v=4"},"body":"Essentially the same, but rejecting the correcting credential this time.\n\nJohn Szakmeister (2):\n  http: store credential when PKI auth is used\n  http: drop the check for an empty proxy password before approving\n\n http.c | 13 +++++++++++--\n 1 file changed, 11 insertions(+), 2 deletions(-)\n\n-- \n2.30.1\n\n"},{"id":"418925","messageId":"20210312024027.33418-2-john@szakmeister.net","threadId":"55298","inReplyTo":"20210312024027.33418-1-john@szakmeister.net","subject":"[PATCH v3 1/2] http: store credential when PKI auth is used","fromName":"John Szakmeister","fromEmail":"john@szakmeister.net","sentAt":"2021-03-12T02:40:26Z","receivedAt":"2021-03-12T02:41:15Z","isPatch":true,"sender":{"key":"john@szakmeister.net","avatar":"https://avatars.githubusercontent.com/u/448087?v=4"},"body":"We already looked for the PKI credentials in the credential store, but\nfailed to approve it on success.  Meaning, the PKI certificate password\nwas never stored and git would request it on every connection to the\nremote.  Let's complete the chain by storing the certificate password on\nsuccess.\n\nLikewise, we also need to reject the credential when there is a failure.\nCurl appears to report client-related certificate issues are reported\nwith the CURLE_SSL_CERTPROBLEM error.  This includes not only a bad\npassword, but potentially other client certificate related problems.\nSince we cannot get more information from curl, we'll go ahead and\nreject the credential upon receiving that error, just to be safe and\navoid caching or saving a bad password.\n\nSigned-off-by: John Szakmeister <john@szakmeister.net>\n---\n http.c | 10 ++++++++++\n 1 file changed, 10 insertions(+)\n\ndiff --git a/http.c b/http.c\nindex f8ea28bb2e..60d01c6e83 100644\n--- a/http.c\n+++ b/http.c\n@@ -1637,7 +1637,17 @@ static int handle_curl_result(struct slot_results *results)\n \t\tcredential_approve(&http_auth);\n \t\tif (proxy_auth.password)\n \t\t\tcredential_approve(&proxy_auth);\n+\t\tcredential_approve(&cert_auth);\n \t\treturn HTTP_OK;\n+\t} else if (results->curl_result == CURLE_SSL_CERTPROBLEM) {\n+\t\t/*\n+\t\t * We can't tell from here whether it's a bad path, bad\n+\t\t * certificate, bad password, or something else wrong\n+\t\t * with the certificate.  So we reject the credential to\n+\t\t * avoid caching or saving a bad password.\n+\t\t */\n+\t\tcredential_reject(&cert_auth);\n+\t\treturn HTTP_NOAUTH;\n \t} else if (missing_target(results))\n \t\treturn HTTP_MISSING_TARGET;\n \telse if (results->http_code == 401) {\n-- \n2.30.1\n\n"},{"id":"418999","messageId":"YEvXPIYbXeTvWhRz@camp.crustytoothpaste.net","threadId":"55298","inReplyTo":"20210312024027.33418-1-john@szakmeister.net","subject":"Re: [PATCH v3 0/2] http: store credential when PKI auth is used","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2021-03-12T21:03:56Z","receivedAt":"2021-03-12T21:05:33Z","isPatch":true,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2021-03-12 at 02:40:25, John Szakmeister wrote:\n> Essentially the same, but rejecting the correcting credential this time.\n> \n> John Szakmeister (2):\n>   http: store credential when PKI auth is used\n>   http: drop the check for an empty proxy password before approving\n> \n>  http.c | 13 +++++++++++--\n>  1 file changed, 11 insertions(+), 2 deletions(-)\n\nI looked and this seems sensible.\n-- \nbrian m. carlson (he/him or they/them)\nHouston, Texas, US\n"}]}