{"thread":{"id":"62777","subject":"[PATCH] docs: discuss caching personal access tokens","startedAt":"2025-01-09T21:27:03Z","lastAt":"2025-01-10T22:54:43Z","messageCount":7,"participants":["M Hickford via GitGitGadget","Junio C Hamano","rsbecker@nexbridge.com","M Hickford"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"510271","messageId":"pull.1851.git.1736458019921.gitgitgadget@gmail.com","threadId":"62777","inReplyTo":null,"subject":"[PATCH] docs: discuss caching personal access tokens","fromName":"M Hickford via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2025-01-09T21:26:59Z","receivedAt":"2025-01-09T21:27:03Z","isPatch":true,"sender":{"key":"mirth.hickford@gmail.com","avatar":"https://avatars.githubusercontent.com/u/105314?v=4"},"body":"From: M Hickford <mirth.hickford@gmail.com>\n\nDescribe problems storing personal access tokens in git-credential-cache\nand suggest alternatives.\n\nResearch suggests that many users are confused about this:\n\n> the point of passwords is that (ideally) you memorise them [so]\n> they're never stored anywhere in plain text. Yet GitHub's personal\n> access token system seems to basically force you to store the token in\n> plain text?\n\nhttps://stackoverflow.com/questions/46645843/where-to-store-my-git-personal-access-token#comment89963004_46645843\nSigned-off-by: M Hickford <mirth.hickford@gmail.com>\n---\n    docs: discuss caching personal access tokens\n\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-1851%2Fhickford%2Fcache-pat-docs-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-1851/hickford/cache-pat-docs-v1\nPull-Request: https://github.com/gitgitgadget/git/pull/1851\n\n Documentation/git-credential-cache.txt | 17 +++++++++++++++++\n 1 file changed, 17 insertions(+)\n\ndiff --git a/Documentation/git-credential-cache.txt b/Documentation/git-credential-cache.txt\nindex 487cc557a87..18e9933674a 100644\n--- a/Documentation/git-credential-cache.txt\n+++ b/Documentation/git-credential-cache.txt\n@@ -78,6 +78,23 @@ variable (this example increases the cache time to 1 hour):\n $ git config credential.helper 'cache --timeout=3600'\n -------------------------------------------------------\n \n+PERSONAL ACCESS TOKENS\n+----------------------\n+\n+Some remotes accept personal access tokens, which are randomly\n+generated and hard to memorise. They typically have a lifetime of weeks\n+or months.\n+\n+git-credential-cache is inherently unsuitable for persistent storage of\n+personal access tokens. The credential will be forgotten after the cache\n+timeout. Even if you configure a long timeout, credentials will be\n+forgotten if the daemon dies.\n+\n+To avoid frequently regenerating personal access tokens, configure a\n+credential helper with persistent storage. Alternatively, configure an\n+OAuth credential helper to generate credentials automatically. See\n+linkgit:gitcredentials[7].\n+\n GIT\n ---\n Part of the linkgit:git[1] suite\n\nbase-commit: 14650065b76b28d3cfa9453356ac5669b19e706e\n-- \ngitgitgadget\n"},{"id":"510335","messageId":"xmqqwmf27cvv.fsf@gitster.g","threadId":"62777","inReplyTo":"pull.1851.git.1736458019921.gitgitgadget@gmail.com","subject":"Re: [PATCH] docs: discuss caching personal access tokens","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2025-01-10T18:16:36Z","receivedAt":"2025-01-10T18:16:39Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"\"M Hickford via GitGitGadget\" <gitgitgadget@gmail.com> writes:\n\n> From: M Hickford <mirth.hickford@gmail.com>\n>\n> Describe problems storing personal access tokens in git-credential-cache\n> and suggest alternatives.\n\n> +PERSONAL ACCESS TOKENS\n> +----------------------\n> +\n> +Some remotes accept personal access tokens, which are randomly\n> +generated and hard to memorise. They typically have a lifetime of weeks\n> +or months.\n> +\n> +git-credential-cache is inherently unsuitable for persistent storage of\n> +personal access tokens. The credential will be forgotten after the cache\n> +timeout. Even if you configure a long timeout, credentials will be\n> +forgotten if the daemon dies.\n\nVery true.\n\n> +To avoid frequently regenerating personal access tokens, configure a\n> +credential helper with persistent storage.\n\nLike libsecret and osxkeychain, you mean?  I am wondering if we want\nto be a bit more helpful by being explicit.  I think there is a\nsection in a maual page that has a list of known and often-used\ncredential backends, so referring the readers to that section may be\nhelpful.\n\n> Alternatively, configure an\n> +OAuth credential helper to generate credentials automatically. See\n> +linkgit:gitcredentials[7].\n\nIndeed.\n"},{"id":"510339","messageId":"017f01db6393$7e3fe2e0$7abfa8a0$@nexbridge.com","threadId":"62777","inReplyTo":"xmqqwmf27cvv.fsf@gitster.g","subject":"RE: [PATCH] docs: discuss caching personal access tokens","fromName":"","fromEmail":"rsbecker@nexbridge.com","sentAt":"2025-01-10T19:11:40Z","receivedAt":"2025-01-10T19:12:05Z","isPatch":true,"sender":{"key":"randall.becker@nexbridge.ca","avatar":"https://avatars.githubusercontent.com/u/28956764?v=4"},"body":"On January 10, 2025 1:17 PM, Junio C Hamano wrote:\n>Subject: Re: [PATCH] docs: discuss caching personal access tokens\n>\n>\"M Hickford via GitGitGadget\" <gitgitgadget@gmail.com> writes:\n>\n>> From: M Hickford <mirth.hickford@gmail.com>\n>>\n>> Describe problems storing personal access tokens in\n>> git-credential-cache and suggest alternatives.\n>\n>> +PERSONAL ACCESS TOKENS\n>> +----------------------\n>> +\n>> +Some remotes accept personal access tokens, which are randomly\n>> +generated and hard to memorise. They typically have a lifetime of\n>> +weeks or months.\n>> +\n>> +git-credential-cache is inherently unsuitable for persistent storage\n>> +of personal access tokens. The credential will be forgotten after the\n>> +cache timeout. Even if you configure a long timeout, credentials will\n>> +be forgotten if the daemon dies.\n>\n>Very true.\n>\n>> +To avoid frequently regenerating personal access tokens, configure a\n>> +credential helper with persistent storage.\n>\n>Like libsecret and osxkeychain, you mean?  I am wondering if we want to be\na bit\n>more helpful by being explicit.  I think there is a section in a maual page\nthat has a\n>list of known and often-used credential backends, so referring the readers\nto that\n>section may be helpful.\n>\n>> Alternatively, configure an\n>> +OAuth credential helper to generate credentials automatically. See\n>> +linkgit:gitcredentials[7].\n>\n>Indeed.\n\nMy solution for this is to write a custom credential manager that is PAT\naware. The one I built\ndoes not support OAuth or OAuth2. This is non-trivial when dealing with a\nCLI. Integrating\nwith something like MS Authenticator might be a reasonable option for some.\n\n"},{"id":"510344","messageId":"CAGJzqsnGt7GSdNT0ToK5WRvQVvtxppRxx6W_y5sHNu2t2k_Rzw@mail.gmail.com","threadId":"62777","inReplyTo":"xmqqwmf27cvv.fsf@gitster.g","subject":"Re: [PATCH] docs: discuss caching personal access tokens","fromName":"M Hickford","fromEmail":"mirth.hickford@gmail.com","sentAt":"2025-01-10T21:25:48Z","receivedAt":"2025-01-10T21:26:29Z","isPatch":true,"sender":{"key":"mirth.hickford@gmail.com","avatar":"https://avatars.githubusercontent.com/u/105314?v=4"},"body":"On Fri, 10 Jan 2025 at 18:16, Junio C Hamano <gitster@pobox.com> wrote:\n>\n> \"M Hickford via GitGitGadget\" <gitgitgadget@gmail.com> writes:\n>\n> > From: M Hickford <mirth.hickford@gmail.com>\n> >\n> > Describe problems storing personal access tokens in git-credential-cache\n> > and suggest alternatives.\n>\n> > +PERSONAL ACCESS TOKENS\n> > +----------------------\n> > +\n> > +Some remotes accept personal access tokens, which are randomly\n> > +generated and hard to memorise. They typically have a lifetime of weeks\n> > +or months.\n> > +\n> > +git-credential-cache is inherently unsuitable for persistent storage of\n> > +personal access tokens. The credential will be forgotten after the cache\n> > +timeout. Even if you configure a long timeout, credentials will be\n> > +forgotten if the daemon dies.\n>\n> Very true.\n>\n> > +To avoid frequently regenerating personal access tokens, configure a\n> > +credential helper with persistent storage.\n>\n> Like libsecret and osxkeychain, you mean?  I am wondering if we want\n> to be a bit more helpful by being explicit.  I think there is a\n> section in a maual page that has a list of known and often-used\n> credential backends, so referring the readers to that section may be\n> helpful.\n\nI agree, explicit is more helpful. I shall expand that\ngitcredentials.txt section in patch v2.\n\n>\n> > Alternatively, configure an\n> > +OAuth credential helper to generate credentials automatically. See\n> > +linkgit:gitcredentials[7].\n>\n> Indeed.\n"},{"id":"510352","messageId":"pull.1851.v2.git.1736549677.gitgitgadget@gmail.com","threadId":"62777","inReplyTo":"pull.1851.git.1736458019921.gitgitgadget@gmail.com","subject":"[PATCH v2 0/2] docs: discuss caching personal access tokens","fromName":"M Hickford via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2025-01-10T22:54:35Z","receivedAt":"2025-01-10T22:54:40Z","isPatch":true,"sender":{"key":"mirth.hickford@gmail.com","avatar":"https://avatars.githubusercontent.com/u/105314?v=4"},"body":"CC: sandals@crustytoothpaste.net CC: derrickstolee@github.com CC:\nstolee@gmail.com CC: Johannes.Schindelin@gmx.de CC: peff@peff.net cc:\nrsbecker@nexbridge.com\n\nPatch v2 adds a list of popular credential helpers.\n\nM Hickford (2):\n  docs: list popular credential helpers\n  docs: discuss caching personal access tokens\n\n Documentation/git-credential-cache.txt | 17 +++++++++++\n Documentation/gitcredentials.txt       | 41 ++++++++++++++++++--------\n 2 files changed, 46 insertions(+), 12 deletions(-)\n\n\nbase-commit: 14650065b76b28d3cfa9453356ac5669b19e706e\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-1851%2Fhickford%2Fcache-pat-docs-v2\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-1851/hickford/cache-pat-docs-v2\nPull-Request: https://github.com/gitgitgadget/git/pull/1851\n\nRange-diff vs v1:\n\n -:  ----------- > 1:  097eb0e8776 docs: list popular credential helpers\n 1:  1980f6a5aa7 ! 2:  ac8c5e1b552 docs: discuss caching personal access tokens\n     @@ Documentation/git-credential-cache.txt: variable (this example increases the cac\n      +To avoid frequently regenerating personal access tokens, configure a\n      +credential helper with persistent storage. Alternatively, configure an\n      +OAuth credential helper to generate credentials automatically. See\n     -+linkgit:gitcredentials[7].\n     ++linkgit:gitcredentials[7], sections \"Available helpers\" and \"OAuth\".\n      +\n       GIT\n       ---\n\n-- \ngitgitgadget\n"},{"id":"510353","messageId":"097eb0e877628c0ac51a8699acaaf5e15d0e2cae.1736549677.git.gitgitgadget@gmail.com","threadId":"62777","inReplyTo":"pull.1851.v2.git.1736549677.gitgitgadget@gmail.com","subject":"[PATCH v2 1/2] docs: list popular credential helpers","fromName":"M Hickford via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2025-01-10T22:54:36Z","receivedAt":"2025-01-10T22:54:41Z","isPatch":true,"sender":{"key":"mirth.hickford@gmail.com","avatar":"https://avatars.githubusercontent.com/u/105314?v=4"},"body":"From: M Hickford <mirth.hickford@gmail.com>\n\ngit-credential-store saves credentials unencrypted on disk. It is the\nleast secure choice of credential helper. Nevertheless, it appears\nseveral times more popular than any other credential helper [1].\n\nInform users about more secure alternatives.\n\n[1] https://stackoverflow.com/questions/35942754/how-can-i-save-username-and-password-in-git\n\nSigned-off-by: M Hickford <mirth.hickford@gmail.com>\n---\n Documentation/gitcredentials.txt | 41 ++++++++++++++++++++++----------\n 1 file changed, 29 insertions(+), 12 deletions(-)\n\ndiff --git a/Documentation/gitcredentials.txt b/Documentation/gitcredentials.txt\nindex 35a7452c8fe..3337bb475de 100644\n--- a/Documentation/gitcredentials.txt\n+++ b/Documentation/gitcredentials.txt\n@@ -66,18 +66,7 @@ storage provided by the OS or other programs. Alternatively, a\n credential-generating helper might generate credentials for certain servers via\n some API.\n \n-To use a helper, you must first select one to use. Git currently\n-includes the following helpers:\n-\n-cache::\n-\n-\tCache credentials in memory for a short period of time. See\n-\tlinkgit:git-credential-cache[1] for details.\n-\n-store::\n-\n-\tStore credentials indefinitely on disk. See\n-\tlinkgit:git-credential-store[1] for details.\n+To use a helper, you must first select one to use (see below for a list).\n \n You may also have third-party helpers installed; search for\n `credential-*` in the output of `git help -a`, and consult the\n@@ -106,6 +95,28 @@ $ git config --global credential.helper foo\n \n === Available helpers\n \n+Git currently includes the following helpers:\n+\n+cache::\n+\n+    Cache credentials in memory for a short period of time. See\n+    linkgit:git-credential-cache[1] for details.\n+\n+store::\n+\n+    Store credentials indefinitely on disk. See\n+    linkgit:git-credential-store[1] for details.\n+\n+Popular helpers with secure persistent storage include:\n+\n+    - git-credential-libsecret (Linux)\n+\n+    - git-credential-osxkeychain (macOS)\n+\n+    - git-credential-wincred (Windows)\n+\n+    - https://github.com/git-ecosystem/git-credential-manager[Git Credential Manager] (cross platform, included in Git for Windows)\n+\n The community maintains a comprehensive list of Git credential helpers at\n https://git-scm.com/doc/credential-helpers.\n \n@@ -116,6 +127,12 @@ OAuth credential helper. Initial authentication opens a browser window to the\n host. Subsequent authentication happens in the background. Many popular Git\n hosts support OAuth.\n \n+Popular helpers with OAuth support include:\n+\n+    - https://github.com/git-ecosystem/git-credential-manager[Git Credential Manager] (cross platform, included in Git for Windows)\n+\n+    - https://github.com/hickford/git-credential-oauth[git-credential-oauth] (cross platform, included in many Linux distributions)\n+\n CREDENTIAL CONTEXTS\n -------------------\n \n-- \ngitgitgadget\n\n"},{"id":"510354","messageId":"ac8c5e1b55289d6a0acc621d1b63fb57822af595.1736549677.git.gitgitgadget@gmail.com","threadId":"62777","inReplyTo":"pull.1851.v2.git.1736549677.gitgitgadget@gmail.com","subject":"[PATCH v2 2/2] docs: discuss caching personal access tokens","fromName":"M Hickford via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2025-01-10T22:54:37Z","receivedAt":"2025-01-10T22:54:43Z","isPatch":true,"sender":{"key":"mirth.hickford@gmail.com","avatar":"https://avatars.githubusercontent.com/u/105314?v=4"},"body":"From: M Hickford <mirth.hickford@gmail.com>\n\nDescribe problems storing personal access tokens in git-credential-cache\nand suggest alternatives.\n\nResearch suggests that many users are confused about this:\n\n> the point of passwords is that (ideally) you memorise them [so]\n> they're never stored anywhere in plain text. Yet GitHub's personal\n> access token system seems to basically force you to store the token in\n> plain text?\n\nhttps://stackoverflow.com/questions/46645843/where-to-store-my-git-personal-access-token#comment89963004_46645843\nSigned-off-by: M Hickford <mirth.hickford@gmail.com>\n---\n Documentation/git-credential-cache.txt | 17 +++++++++++++++++\n 1 file changed, 17 insertions(+)\n\ndiff --git a/Documentation/git-credential-cache.txt b/Documentation/git-credential-cache.txt\nindex 487cc557a87..54fa7a27e19 100644\n--- a/Documentation/git-credential-cache.txt\n+++ b/Documentation/git-credential-cache.txt\n@@ -78,6 +78,23 @@ variable (this example increases the cache time to 1 hour):\n $ git config credential.helper 'cache --timeout=3600'\n -------------------------------------------------------\n \n+PERSONAL ACCESS TOKENS\n+----------------------\n+\n+Some remotes accept personal access tokens, which are randomly\n+generated and hard to memorise. They typically have a lifetime of weeks\n+or months.\n+\n+git-credential-cache is inherently unsuitable for persistent storage of\n+personal access tokens. The credential will be forgotten after the cache\n+timeout. Even if you configure a long timeout, credentials will be\n+forgotten if the daemon dies.\n+\n+To avoid frequently regenerating personal access tokens, configure a\n+credential helper with persistent storage. Alternatively, configure an\n+OAuth credential helper to generate credentials automatically. See\n+linkgit:gitcredentials[7], sections \"Available helpers\" and \"OAuth\".\n+\n GIT\n ---\n Part of the linkgit:git[1] suite\n-- \ngitgitgadget\n"}]}