{"thread":{"id":"66375","subject":"[BUG] basic auth not send on empty password in default configuration","startedAt":"2026-09-23T07:10:15Z","lastAt":"2026-09-23T07:10:15Z","messageCount":1,"participants":["Xavier Morel"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"553032","messageId":"6fa4c795-7f80-45e7-a42a-ee6e9cfc01cf@odoo.com","threadId":"66375","inReplyTo":null,"subject":"[BUG] basic auth not send on empty password in default configuration","fromName":"Xavier Morel","fromEmail":"xmo@odoo.com","sentAt":"2026-09-23T07:10:11Z","receivedAt":"2026-09-23T07:10:15Z","isPatch":false,"body":"Hit this issue playing with a custom credential helper:\n\n- if the server requires authentication for an operation (returns 401 on\n   an un-authenticated request)\n- and the credential helper sets an empty username and a non-empty\n   password\n- the second request git sends is still un-authenticated instead of\n   having basic auth set\n- git then fails with an \"authentication failed\" error\n\nIf proactiveAuth=basic is enabled, git doesn't mind the empty username\nand sends the request with basic auth set.\n\nThis was directly observed on git 2.47 and 2.55, with curl 8.5.0.\n\nThe issue seems to come from init_curl_http_auth: if the username is\nunset *or empty*, it exits immediately unless proactive auth is enabled,\nwhich matches the symptoms. From this it looks like an other workaround\nwould be for the credential helper to precompute the `credential` value\nand return that instead of username/password, as that is guaranteed to \nbe non-empty.\n\nEither way the current behaviour is somewhat surprising as (AFAIK)\nnothing in basic auth requires non-empty usernames (or even passwords),\nand importantly git doesn't report anything odd except the connection\nfailing, the lack of auth on the second attempt is only visible when\nenabling GIT_CURL_VERBOSE and comparing a successful auth with an\nunsuccessful one (or on the server side, but there if the server is\nbespoke one can easily chase ghosts assuming the error is obviously\nsomewhere in the bespoke code because select isn't broken).\n"}]}