git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] fetch: Strip usernames from url's before storing them

From
Andreas Ericsson <ae@op5.se>
Date
Apr 15, 2009, 12:16 UTC
Message-ID
<1239797816-24582-1-git-send-email-ae@op5.se>

When pulling from a remote, the full URL including username is by default added to the commit message. Since it adds very little value but could be used by malicious people to glean valid usernames (with matching hostnames), we're far better off just stripping the username before storing the remote URL locally.

Signed-off-by: Andreas Ericsson <ae@op5.se>
---
 builtin-fetch.c |   48 ++++++++++++++++++++++++++++++++++++++++++++++--
 1 files changed, 46 insertions(+), 2 deletions(-)
diff --git a/builtin-fetch.c b/builtin-fetch.c
index 3c998ea..47fba00 100644
--- a/builtin-fetch.c
+++ b/builtin-fetch.c
@@ -289,7 +289,48 @@ static int update_local_ref(struct ref *ref,
 	}
 }
 
-static int store_updated_refs(const char *url, const char *remote_name,
+/*
+ * strip username information from the url
+ * This will allocate a new string, or return its argument
+ * if no stripping is necessary.
+ *
+ * The url's we want to catch are the following:
+ *   ssh://[user@]host.xz[:port]/path/to/repo.git/
+ *   [user@]host.xz:/path/to/repo.git/
+ *   http[s]://[user[:password]@]host.xz/path/to/repo.git
+ *
+ * Although git doesn't currently support giving the password
+ * to http url's on the command-line, it's easier to catch
+ * that case too than it is to cater for it specially.
+ */
+static char *anonymize_url(const char *url)
+{
+	char *anon_url;
+	const char *at_sign = strchr(url, '@');
+	size_t prefix_len = 0;
+
+	if (!at_sign)
+		return strdup(url);
+
+	if (!prefixcmp(url, "ssh://"))
+		prefix_len = strlen("ssh://");
+	else if (!prefixcmp(url, "http://"))
+		prefix_len = strlen("http://");
+	else if (!prefixcmp(url, "https://"))
+		prefix_len = strlen("https://");
+	else if (!strchr(at_sign + 1, ':'))
+		return strdup(url);
+
+	anon_url = xcalloc(1, 1 + prefix_len +
+			   ((unsigned long)at_sign - (unsigned long)url));
+	if (prefix_len)
+		memcpy(anon_url, url, prefix_len);
+	memcpy(anon_url + prefix_len, at_sign + 1, strlen(at_sign + 1));
+
+	return anon_url;
+}
+
+static int store_updated_refs(const char *raw_url, const char *remote_name,
 		struct ref *ref_map)
 {
 	FILE *fp;
@@ -298,11 +339,13 @@ static int store_updated_refs(const char *url, const char *remote_name,
 	char note[1024];
 	const char *what, *kind;
 	struct ref *rm;
-	char *filename = git_path("FETCH_HEAD");
+	char *url, *filename = git_path("FETCH_HEAD");
 
 	fp = fopen(filename, "a");
 	if (!fp)
 		return error("cannot open %s: %s\n", filename, strerror(errno));
+
+	url = anonymize_url(raw_url);
 	for (rm = ref_map; rm; rm = rm->next) {
 		struct ref *ref = NULL;
 
@@ -376,6 +419,7 @@ static int store_updated_refs(const char *url, const char *remote_name,
 				fprintf(stderr, " %s\n", note);
 		}
 	}
+	free(url);
 	fclose(fp);
 	if (rc & 2)
 		error("some local refs could not be updated; try running\n"
-- 
1.6.3.rc0.2.g7cd31
Next: Michael J Gruber
Message 1 of 13 in “fetch: Strip usernames from url's before storing them”
  1. fetch: Strip usernames from url's before storing themAndreas Ericsson, Apr 15, 2009
  2. Michael J GruberApr 15, 2009
  3. Andreas EricssonApr 15, 2009
  4. Junio C HamanoApr 15, 2009
  5. Andreas EricssonApr 15, 2009
  6. Johannes SixtApr 15, 2009
  7. Andreas EricssonApr 15, 2009
  8. fetch: Strip usernames from url's before storing themAndreas Ericsson, Apr 15, 2009
  9. Junio C HamanoApr 15, 2009
  10. Andreas EricssonApr 15, 2009
  11. fetch: Strip usernames from url's before storing themAndreas Ericsson, Apr 17, 2009
  12. Andreas EricssonApr 20, 2009
  13. Junio C HamanoApr 20, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.