{"thread":{"id":"64319","subject":"[PATCH] http.c: prompt for username on 403","startedAt":"2025-10-14T14:50:59Z","lastAt":"2025-12-11T06:10:43Z","messageCount":11,"participants":["Ashlesh Gawande","brian m. carlson","rsbecker@nexbridge.com"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"528740","messageId":"20251014144354.1457818-2-git@ashlesh.me","threadId":"64319","inReplyTo":null,"subject":"[PATCH] http.c: prompt for username on 403","fromName":"Ashlesh Gawande","fromEmail":"git@ashlesh.me","sentAt":"2025-10-14T14:43:52Z","receivedAt":"2025-10-14T14:50:59Z","isPatch":true,"sender":{"key":"git@ashlesh.me","avatar":"https://avatars.githubusercontent.com/u/8251376?v=4"},"body":"Scenario:\n- There are a few pre-production systems that a lot of testers and\n  developers need to time share because of low availability\n- Devops generates a GitHub token with pull only access\n  and adds it to the netrc file on these systems\n  (Pull only as we don't want testers/others to be able to push)\n- Testers log in and do a git pull for the latest changes\n  (via netrc credentials - though testers may not be aware)\n- Developers login to debug issues and may make fixes to the test repo\n- Now when developers try to push their changes they receive:\n  fatal: unable to access 'https://github.com/<org>/<project>/':\n  The requested URL returned error: 403\n- The developer is not given the chance to supply an authorized token\n  and either needs to comment the netrc file or copy the changes over\n  to their own machine\n\nSigned-off-by: Ashlesh Gawande <git@ashlesh.me>\n---\n http.c                     |  2 +-\n t/lib-httpd.sh             |  9 +++++++++\n t/lib-httpd/apache.conf    |  4 ++++\n t/lib-httpd/passwd         |  1 +\n t/t5550-http-fetch-dumb.sh | 24 ++++++++++++++++++++++++\n 5 files changed, 39 insertions(+), 1 deletion(-)\n\ndiff --git a/http.c b/http.c\nindex 7e3af1e72f..18959f63b9 100644\n--- a/http.c\n+++ b/http.c\n@@ -1852,7 +1852,7 @@ static int handle_curl_result(struct slot_results *results)\n \t\treturn HTTP_NOMATCHPUBLICKEY;\n \t} else if (missing_target(results))\n \t\treturn HTTP_MISSING_TARGET;\n-\telse if (results->http_code == 401) {\n+\telse if (results->http_code == 401 || results->http_code == 403) {\n \t\tif ((http_auth.username && http_auth.password) ||\\\n \t\t    (http_auth.authtype && http_auth.credential)) {\n \t\t\tif (http_auth.multistage) {\ndiff --git a/t/lib-httpd.sh b/t/lib-httpd.sh\nindex 5091db949b..cdc92b2916 100644\n--- a/t/lib-httpd.sh\n+++ b/t/lib-httpd.sh\n@@ -325,6 +325,15 @@ set_askpass() {\n \techo \"$2\" >\"$TRASH_DIRECTORY/askpass-pass\"\n }\n \n+set_netrc() {\n+\t# $HOME=$TRASH_DIRECTORY\n+\techo \"machine $1 login $2 password $3\" > $TRASH_DIRECTORY/.netrc\n+}\n+\n+clear_netrc() {\n+\trm \"$TRASH_DIRECTORY/.netrc\"\n+}\n+\n expect_askpass() {\n \tdest=$HTTPD_DEST${3+/$3}\n \ndiff --git a/t/lib-httpd/apache.conf b/t/lib-httpd/apache.conf\nindex e631ab0eb5..6b8c50a51a 100644\n--- a/t/lib-httpd/apache.conf\n+++ b/t/lib-httpd/apache.conf\n@@ -238,6 +238,10 @@ SSLEngine On\n \tAuthName \"git-auth\"\n \tAuthUserFile passwd\n \tRequire valid-user\n+\n+\t# return 403 for authenticated user: forbidden-user@host\n+\tRewriteCond \"%{REMOTE_USER}\" \"^forbidden-user@host\"\n+\tRewriteRule ^ - [F]\n </Location>\n \n <LocationMatch \"^/auth-push/.*/git-receive-pack$\">\ndiff --git a/t/lib-httpd/passwd b/t/lib-httpd/passwd\nindex d9c122f348..3bab7b6423 100644\n--- a/t/lib-httpd/passwd\n+++ b/t/lib-httpd/passwd\n@@ -1 +1,2 @@\n user@host:$apr1$LGPmCZWj$9vxEwj5Z5GzQLBMxp3mCx1\n+forbidden-user@host:$apr1$LGPmCZWj$9vxEwj5Z5GzQLBMxp3mCx1\ndiff --git a/t/t5550-http-fetch-dumb.sh b/t/t5550-http-fetch-dumb.sh\nindex ed0ad66fad..6c4c1cafb2 100755\n--- a/t/t5550-http-fetch-dumb.sh\n+++ b/t/t5550-http-fetch-dumb.sh\n@@ -102,6 +102,30 @@ test_expect_success 'cloning password-protected repository can fail' '\n \texpect_askpass both wrong\n '\n \n+test_expect_success 'using credentials from netrc to clone successfully' '\n+\tset_askpass wrong &&\n+\tset_netrc 127.0.0.1 user@host pass@host &&\n+\tgit clone \"$HTTPD_URL/auth/dumb/repo.git\" clone-auth-netrc &&\n+\texpect_askpass none\n+'\n+clear_netrc\n+\n+test_expect_success 'netrc unauthorized credentials (prompt after 401)' '\n+\tset_askpass wrong &&\n+\tset_netrc 127.0.0.1 user@host pass@wrong &&\n+\ttest_must_fail git clone \"$HTTPD_URL/auth/dumb/repo.git\" clone-auth-netrc-401 &&\n+\texpect_askpass both wrong\n+'\n+clear_netrc\n+\n+test_expect_success 'netrc authorized but forbidden credentials (prompt after 403)' '\n+\tset_askpass wrong &&\n+\tset_netrc 127.0.0.1 forbidden-user@host pass@host &&\n+\ttest_must_fail git clone \"$HTTPD_URL/auth/dumb/repo.git\" clone-auth-netc-403 &&\n+\texpect_askpass both wrong\n+'\n+clear_netrc\n+\n test_expect_success 'http auth can use user/pass in URL' '\n \tset_askpass wrong &&\n \tgit clone \"$HTTPD_URL_USER_PASS/auth/dumb/repo.git\" clone-auth-none &&\n-- \n2.43.0\n\n"},{"id":"528768","messageId":"aO7Aqooz-0ppbcMP@fruit.crustytoothpaste.net","threadId":"64319","inReplyTo":"20251014144354.1457818-2-git@ashlesh.me","subject":"Re: [PATCH] http.c: prompt for username on 403","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2025-10-14T21:29:14Z","receivedAt":"2025-10-14T21:29:16Z","isPatch":true,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2025-10-14 at 14:43:52, Ashlesh Gawande wrote:\n> Scenario:\n> - There are a few pre-production systems that a lot of testers and\n>   developers need to time share because of low availability\n> - Devops generates a GitHub token with pull only access\n>   and adds it to the netrc file on these systems\n>   (Pull only as we don't want testers/others to be able to push)\n> - Testers log in and do a git pull for the latest changes\n>   (via netrc credentials - though testers may not be aware)\n> - Developers login to debug issues and may make fixes to the test repo\n> - Now when developers try to push their changes they receive:\n>   fatal: unable to access 'https://github.com/<org>/<project>/':\n>   The requested URL returned error: 403\n> - The developer is not given the chance to supply an authorized token\n>   and either needs to comment the netrc file or copy the changes over\n>   to their own machine\n> \n> Signed-off-by: Ashlesh Gawande <git@ashlesh.me>\n> ---\n>  http.c                     |  2 +-\n>  t/lib-httpd.sh             |  9 +++++++++\n>  t/lib-httpd/apache.conf    |  4 ++++\n>  t/lib-httpd/passwd         |  1 +\n>  t/t5550-http-fetch-dumb.sh | 24 ++++++++++++++++++++++++\n>  5 files changed, 39 insertions(+), 1 deletion(-)\n> \n> diff --git a/http.c b/http.c\n> index 7e3af1e72f..18959f63b9 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -1852,7 +1852,7 @@ static int handle_curl_result(struct slot_results *results)\n>  \t\treturn HTTP_NOMATCHPUBLICKEY;\n>  \t} else if (missing_target(results))\n>  \t\treturn HTTP_MISSING_TARGET;\n> -\telse if (results->http_code == 401) {\n> +\telse if (results->http_code == 401 || results->http_code == 403) {\n\nI don't think this is a good idea.  Existing servers send a 401 when no\ncredentials are available and 403 if credentials are sent but are not\nvalid for a repository.  The former case causes credentials to be\nerased, but the latter does not.\n\nYour proposal will cause someone's credentials to be erased just because\nthey don't have access to a repository, which would be bad because it's\nnot that the credentials are invalid (that would be a 401) but that the\ncredentials are not usable for that repository or for that operation.\n\nSo if I attempt to push to https://github.com/git/git.git, then my\ncredentials will be erased even though there are no valid credentials\nthat could possibly grant me access to that repository (because I'm not\nJunio).  Then _none_ of my pushes work because my token is gone.\n\nI agree that it's inconvenient that netrc credential override other\ncredentials, but the proper thing to do would be to (a) not share\nworking trees among users (since Git's security model doesn't allow for\nthat), (b) not use netrc for this purpose and use a credential helper,\n(c) add functionality to disable netrc via config, or (d) use an SSH\ndeploy key for automated systems with `GIT_SSH_COMMAND` and `ssh -i` and\nhave developers forward their SSH agent to push.\n-- \nbrian m. carlson (they/them)\nToronto, Ontario, CA\n"},{"id":"528816","messageId":"30639771-4999-45f4-a8d7-1ed4774ffd8e@ashlesh.me","threadId":"64319","inReplyTo":"aO7Aqooz-0ppbcMP@fruit.crustytoothpaste.net","subject":"Re: [PATCH] http.c: prompt for username on 403","fromName":"Ashlesh Gawande","fromEmail":"git@ashlesh.me","sentAt":"2025-10-15T14:12:09Z","receivedAt":"2025-10-15T14:17:56Z","isPatch":true,"sender":{"key":"git@ashlesh.me","avatar":"https://avatars.githubusercontent.com/u/8251376?v=4"},"body":"\nOn 10/15/25 02:59, brian m. carlson wrote:\n> On 2025-10-14 at 14:43:52, Ashlesh Gawande wrote:\n>> Scenario:\n>> - There are a few pre-production systems that a lot of testers and\n>>    developers need to time share because of low availability\n>> - Devops generates a GitHub token with pull only access\n>>    and adds it to the netrc file on these systems\n>>    (Pull only as we don't want testers/others to be able to push)\n>> - Testers log in and do a git pull for the latest changes\n>>    (via netrc credentials - though testers may not be aware)\n>> - Developers login to debug issues and may make fixes to the test repo\n>> - Now when developers try to push their changes they receive:\n>>    fatal: unable to access 'https://github.com/<org>/<project>/':\n>>    The requested URL returned error: 403\n>> - The developer is not given the chance to supply an authorized token\n>>    and either needs to comment the netrc file or copy the changes over\n>>    to their own machine\n>>\n>> Signed-off-by: Ashlesh Gawande <git@ashlesh.me>\n>> ---\n>>   http.c                     |  2 +-\n>>   t/lib-httpd.sh             |  9 +++++++++\n>>   t/lib-httpd/apache.conf    |  4 ++++\n>>   t/lib-httpd/passwd         |  1 +\n>>   t/t5550-http-fetch-dumb.sh | 24 ++++++++++++++++++++++++\n>>   5 files changed, 39 insertions(+), 1 deletion(-)\n>>\n>> diff --git a/http.c b/http.c\n>> index 7e3af1e72f..18959f63b9 100644\n>> --- a/http.c\n>> +++ b/http.c\n>> @@ -1852,7 +1852,7 @@ static int handle_curl_result(struct slot_results *results)\n>>   \t\treturn HTTP_NOMATCHPUBLICKEY;\n>>   \t} else if (missing_target(results))\n>>   \t\treturn HTTP_MISSING_TARGET;\n>> -\telse if (results->http_code == 401) {\n>> +\telse if (results->http_code == 401 || results->http_code == 403) {\n> I don't think this is a good idea.  Existing servers send a 401 when no\n> credentials are available and 403 if credentials are sent but are not\n> valid for a repository.  The former case causes credentials to be\n> erased, but the latter does not.\n>\n> Your proposal will cause someone's credentials to be erased just because\n> they don't have access to a repository, which would be bad because it's\n> not that the credentials are invalid (that would be a 401) but that the\n> credentials are not usable for that repository or for that operation.\n>\n> So if I attempt to push to https://github.com/git/git.git, then my\n> credentials will be erased even though there are no valid credentials\n> that could possibly grant me access to that repository (because I'm not\n> Junio).  Then _none_ of my pushes work because my token is gone.\n>\n> I agree that it's inconvenient that netrc credential override other\n> credentials, but the proper thing to do would be to (a) not share\n> working trees among users (since Git's security model doesn't allow for\n> that), (b) not use netrc for this purpose and use a credential helper,\n> (c) add functionality to disable netrc via config, or (d) use an SSH\n> deploy key for automated systems with `GIT_SSH_COMMAND` and `ssh -i` and\n> have developers forward their SSH agent to push.\nOh I see - yeah don't want to erase the credentials.\nWas trying to figure why 403 was happening instead of a prompt (as I was \nnot aware of netrc file being used).\nThanks for the detailed explanation and suggestions Brian!\n\nIs it worth it to include the netrc tests in git that I wrote as part of \nthis\n\n(if so I can email them as a separate patch)?\n\nThanks\nAshlesh\n"},{"id":"528921","messageId":"aPAg3gYwzA9fHCC3@fruit.crustytoothpaste.net","threadId":"64319","inReplyTo":"30639771-4999-45f4-a8d7-1ed4774ffd8e@ashlesh.me","subject":"Re: [PATCH] http.c: prompt for username on 403","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2025-10-15T22:31:58Z","receivedAt":"2025-10-15T22:31:59Z","isPatch":true,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2025-10-15 at 14:12:09, Ashlesh Gawande wrote:\n> Oh I see - yeah don't want to erase the credentials.\n> Was trying to figure why 403 was happening instead of a prompt (as I was not\n> aware of netrc file being used).\n> Thanks for the detailed explanation and suggestions Brian!\n> \n> Is it worth it to include the netrc tests in git that I wrote as part of\n> this\n\nYes, I think if you have patches to test our netrc handling, those would\nbe very welcome.  I was complaining a couple months ago about how we had\nno tests for netrc after I accidentally broke the code that makes it\nwork, so I would very much appreciate any tests we could add to make\nthat less likely in the future.\n-- \nbrian m. carlson (they/them)\nToronto, Ontario, CA\n"},{"id":"531895","messageId":"79d2226c-b568-4385-a618-f0d3c06cd0a8@ashlesh.me","threadId":"64319","inReplyTo":"aPAg3gYwzA9fHCC3@fruit.crustytoothpaste.net","subject":"Re: [PATCH] http.c: prompt for username on 403","fromName":"Ashlesh Gawande","fromEmail":"git@ashlesh.me","sentAt":"2025-12-09T08:22:49Z","receivedAt":"2025-12-09T08:28:24Z","isPatch":true,"sender":{"key":"git@ashlesh.me","avatar":"https://avatars.githubusercontent.com/u/8251376?v=4"},"body":"\nOn 10/16/25 04:01, brian m. carlson wrote:\n> On 2025-10-15 at 14:12:09, Ashlesh Gawande wrote:\n>> Oh I see - yeah don't want to erase the credentials.\n>> Was trying to figure why 403 was happening instead of a prompt (as I was not\n>> aware of netrc file being used).\n>> Thanks for the detailed explanation and suggestions Brian!\n>>\n>> Is it worth it to include the netrc tests in git that I wrote as part of\n>> this\n> Yes, I think if you have patches to test our netrc handling, those would\n> be very welcome.  I was complaining a couple months ago about how we had\n> no tests for netrc after I accidentally broke the code that makes it\n> work, so I would very much appreciate any tests we could add to make\n> that less likely in the future.\n\nI was working on separating the tests and thought about the original \nproposal a bit more.\nTo stop the credentials from being erased on 403 could something like \nthe following be acceptable?\n\n         else if (results->http_code == 401 || results->http_code == 403) {\n                 if ((http_auth.username && http_auth.password) ||\\\n                     (http_auth.authtype && http_auth.credential)) {\n+                       // Do not override existing credentials on 403\n+                       if (results->http_code == 403) {\n+                               return HTTP_ERROR;\n+                       }\n+\n                         if (http_auth.multistage) {\n\nSo then we would prompt on 403 only if credentials are not configured.\n\n"},{"id":"531939","messageId":"aTjVenutFBprwrrz@fruit.crustytoothpaste.net","threadId":"64319","inReplyTo":"79d2226c-b568-4385-a618-f0d3c06cd0a8@ashlesh.me","subject":"Re: [PATCH] http.c: prompt for username on 403","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2025-12-10T02:05:46Z","receivedAt":"2025-12-10T02:05:54Z","isPatch":true,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2025-12-09 at 08:22:49, Ashlesh Gawande wrote:\n> I was working on separating the tests and thought about the original\n> proposal a bit more.\n> To stop the credentials from being erased on 403 could something like the\n> following be acceptable?\n> \n>         else if (results->http_code == 401 || results->http_code == 403) {\n>                 if ((http_auth.username && http_auth.password) ||\\\n>                     (http_auth.authtype && http_auth.credential)) {\n> +                       // Do not override existing credentials on 403\n> +                       if (results->http_code == 403) {\n> +                               return HTTP_ERROR;\n> +                       }\n> +\n>                         if (http_auth.multistage) {\n> \n> So then we would prompt on 403 only if credentials are not configured.\n\nCan you tell me what file you see this in?  I don't actually see any\nplace in the code that has \"http_code == 403\" in the latest version of\nthe main branch.\n\nI wonder if your issue may already be fixed in a newer version than you\nhave.\n-- \nbrian m. carlson (they/them)\nToronto, Ontario, CA\n"},{"id":"531965","messageId":"37c3b31e-900e-4df0-ac30-284e71660487@ashlesh.me","threadId":"64319","inReplyTo":"aTjVenutFBprwrrz@fruit.crustytoothpaste.net","subject":"Re: [PATCH] http.c: prompt for username on 403","fromName":"Ashlesh Gawande","fromEmail":"git@ashlesh.me","sentAt":"2025-12-10T12:30:27Z","receivedAt":"2025-12-10T12:35:46Z","isPatch":true,"sender":{"key":"git@ashlesh.me","avatar":"https://avatars.githubusercontent.com/u/8251376?v=4"},"body":"\nOn 12/10/25 07:35, brian m. carlson wrote:\n> On 2025-12-09 at 08:22:49, Ashlesh Gawande wrote:\n>> I was working on separating the tests and thought about the original\n>> proposal a bit more.\n>> To stop the credentials from being erased on 403 could something like the\n>> following be acceptable?\n>>\n>>          else if (results->http_code == 401 || results->http_code == 403) {\n>>                  if ((http_auth.username && http_auth.password) ||\\\n>>                      (http_auth.authtype && http_auth.credential)) {\n>> +                       // Do not override existing credentials on 403\n>> +                       if (results->http_code == 403) {\n>> +                               return HTTP_ERROR;\n>> +                       }\n>> +\n>>                          if (http_auth.multistage) {\n>>\n>> So then we would prompt on 403 only if credentials are not configured.\n> Can you tell me what file you see this in?  I don't actually see any\n> place in the code that has \"http_code == 403\" in the latest version of\n> the main branch.\n>\n> I wonder if your issue may already be fixed in a newer version than you\n> have.\nOh, that http_code == 403 is my original proposal to prompt for \nusername/password on 403 (I did the diff on top of that instead of base).\nBut you pointed out that it would wipe out existing credentials. This is \nan attempt to fix that by not prompting on 403 if git credentials are set.\nSo when credentials are provided through default netrc file (such that \nhttp_auth.* are not set; git credential helper is not set) then we can \nstill get the prompt on 403.\n"},{"id":"531966","messageId":"82aa2f9c-9418-4d4d-bf4b-a813a6fe02d4@ashlesh.me","threadId":"64319","inReplyTo":"aTjVenutFBprwrrz@fruit.crustytoothpaste.net","subject":"Re: [PATCH] http.c: prompt for username on 403","fromName":"Ashlesh Gawande","fromEmail":"git@ashlesh.me","sentAt":"2025-12-10T12:32:42Z","receivedAt":"2025-12-10T12:38:22Z","isPatch":true,"sender":{"key":"git@ashlesh.me","avatar":"https://avatars.githubusercontent.com/u/8251376?v=4"},"body":"\nOn 12/10/25 07:35, brian m. carlson wrote:\n> On 2025-12-09 at 08:22:49, Ashlesh Gawande wrote:\n>> I was working on separating the tests and thought about the original\n>> proposal a bit more.\n>> To stop the credentials from being erased on 403 could something like the\n>> following be acceptable?\n>>\n>>          else if (results->http_code == 401 || results->http_code == 403) {\n>>                  if ((http_auth.username && http_auth.password) ||\\\n>>                      (http_auth.authtype && http_auth.credential)) {\n>> +                       // Do not override existing credentials on 403\n>> +                       if (results->http_code == 403) {\n>> +                               return HTTP_ERROR;\n>> +                       }\n>> +\n>>                          if (http_auth.multistage) {\n>>\n>> So then we would prompt on 403 only if credentials are not configured.\n> Can you tell me what file you see this in?  I don't actually see any\n> place in the code that has \"http_code == 403\" in the latest version of\n> the main branch.\n>\n> I wonder if your issue may already be fixed in a newer version than you\n> have.\nOh, that http_code == 403 is my original proposal to prompt for \nusername/password on 403 (I did the diff on top of that instead of base).\nBut you pointed out that it would wipe out existing credentials. This is \nan attempt to fix that by not prompting on 403 if git credentials are set.\nSo when credentials are provided through default netrc file (such that \nhttp_auth.* are not set; git credential helper is not set) then we can \nstill get the prompt on 403.\n"},{"id":"531995","messageId":"03ed01dc69fd$45f32fc0$d1d98f40$@nexbridge.com","threadId":"64319","inReplyTo":"37c3b31e-900e-4df0-ac30-284e71660487@ashlesh.me","subject":"RE: [PATCH] http.c: prompt for username on 403","fromName":"","fromEmail":"rsbecker@nexbridge.com","sentAt":"2025-12-10T17:48:57Z","receivedAt":"2025-12-10T17:49:19Z","isPatch":true,"sender":{"key":"randall.becker@nexbridge.ca","avatar":"https://avatars.githubusercontent.com/u/28956764?v=4"},"body":"On December 10, 2025 7:30 AM, Ashlesh Gawande wrote:\n>On 12/10/25 07:35, brian m. carlson wrote:\n>> On 2025-12-09 at 08:22:49, Ashlesh Gawande wrote:\n>>> I was working on separating the tests and thought about the original\n>>> proposal a bit more.\n>>> To stop the credentials from being erased on 403 could something like\n>>> the following be acceptable?\n>>>\n>>>          else if (results->http_code == 401 || results->http_code ==\n>>> 403) {\n>>>                  if ((http_auth.username && http_auth.password) ||\\\n>>>                      (http_auth.authtype && http_auth.credential)) {\n>>> +                       // Do not override existing credentials on\n>>> +403\n>>> +                       if (results->http_code == 403) {\n>>> +                               return HTTP_ERROR;\n>>> +                       }\n>>> +\n>>>                          if (http_auth.multistage) {\n>>>\n>>> So then we would prompt on 403 only if credentials are not configured.\n>> Can you tell me what file you see this in?  I don't actually see any\n>> place in the code that has \"http_code == 403\" in the latest version of\n>> the main branch.\n>>\n>> I wonder if your issue may already be fixed in a newer version than\n>> you have.\n>Oh, that http_code == 403 is my original proposal to prompt for\n>username/password on 403 (I did the diff on top of that instead of base).\n>But you pointed out that it would wipe out existing credentials. This is an attempt to\n>fix that by not prompting on 403 if git credentials are set.\n>So when credentials are provided through default netrc file (such that\n>http_auth.* are not set; git credential helper is not set) then we can still get the\n>prompt on 403.\n\nPlease make sure that any existing git credential helpers, including custom helpers\nare not impacted by this change. This would have serious negative consequences\nand would be a blocker for many in my community who use both the standard\ngit credential helpers and custom ones. If you are going to force a credential wipe\nthis should cause an update to the credential protocol to inform the helper that a\nwipe has occurred or is requested. The .netrc approach is most limited to Linux\nimplementations and is not available on or applicable to some other platforms.\n\nThank you for your attention.\nRandall\n\n\n"},{"id":"532005","messageId":"aTn0BOM07Lyphq_1@fruit.crustytoothpaste.net","threadId":"64319","inReplyTo":"37c3b31e-900e-4df0-ac30-284e71660487@ashlesh.me","subject":"Re: [PATCH] http.c: prompt for username on 403","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2025-12-10T22:28:20Z","receivedAt":"2025-12-10T22:28:23Z","isPatch":true,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2025-12-10 at 12:30:27, Ashlesh Gawande wrote:\n> Oh, that http_code == 403 is my original proposal to prompt for\n> username/password on 403 (I did the diff on top of that instead of base).\n> But you pointed out that it would wipe out existing credentials. This is an\n> attempt to fix that by not prompting on 403 if git credentials are set.\n> So when credentials are provided through default netrc file (such that\n> http_auth.* are not set; git credential helper is not set) then we can still\n> get the prompt on 403.\n\nAs Randall said, I don't think it's a good idea to do this.  It's a\nmajor change in how functionality works and it will probably break\nusers.\n\nI did mention before that a better approach is to add a config to decide\nwhether to honour the netrc and I think that would be the right choice\nhere.  That lets people opt into different behaviour if they want it\n(and, to be honest, I _do_ very much want to skip netrc for Git\ncredentials since I have similar problems as the ones you're describing)\nand avoids breaking things for existing users.\n-- \nbrian m. carlson (they/them)\nToronto, Ontario, CA\n"},{"id":"532021","messageId":"888e3dec-e279-47af-8a91-04a06f6eb0af@ashlesh.me","threadId":"64319","inReplyTo":"aTn0BOM07Lyphq_1@fruit.crustytoothpaste.net","subject":"Re: [PATCH] http.c: prompt for username on 403","fromName":"Ashlesh Gawande","fromEmail":"git@ashlesh.me","sentAt":"2025-12-11T06:05:11Z","receivedAt":"2025-12-11T06:10:43Z","isPatch":true,"sender":{"key":"git@ashlesh.me","avatar":"https://avatars.githubusercontent.com/u/8251376?v=4"},"body":"\nOn 12/11/25 03:58, brian m. carlson wrote:\n> On 2025-12-10 at 12:30:27, Ashlesh Gawande wrote:\n>> Oh, that http_code == 403 is my original proposal to prompt for\n>> username/password on 403 (I did the diff on top of that instead of base).\n>> But you pointed out that it would wipe out existing credentials. This is an\n>> attempt to fix that by not prompting on 403 if git credentials are set.\n>> So when credentials are provided through default netrc file (such that\n>> http_auth.* are not set; git credential helper is not set) then we can still\n>> get the prompt on 403.\n> As Randall said, I don't think it's a good idea to do this.  It's a\n> major change in how functionality works and it will probably break\n> users.\n>\n> I did mention before that a better approach is to add a config to decide\n> whether to honour the netrc and I think that would be the right choice\n> here.  That lets people opt into different behaviour if they want it\n> (and, to be honest, I _do_ very much want to skip netrc for Git\n> credentials since I have similar problems as the ones you're describing)\n> and avoids breaking things for existing users.\n\nHmm, okay I understand. Yes probably good idea to skip netrc for Git \ncredentials.\nThank you for your input Brian and Randall!\n\n"}]}