git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH 1/4] Document the HTTP transport protocol

From
Shawn O. Pearce <spearce@spearce.org>
Date
Oct 15, 2009, 16:52 UTC
Message-ID
<20091015165228.GO10505@spearce.org>
In-Reply-To
<20091009195035.GA15153@coredump.intra.peff.net>
Jeff King <peff@peff.net> wrote:
Show 9 quoted lines
> On Thu, Oct 08, 2009 at 10:22:45PM -0700, Shawn O. Pearce wrote:
> > +Servers MUST NOT require HTTP cookies for the purposes of
> > +authentication or access control.
> > [...]
> > +Servers MUST NOT require HTTP cookies in order to function correctly.
> 
> Why not? I can grant that the current git implementation probably can't
> handle it, but keep in mind this is talking about the protocol and not
> the implementation.

Good point... this document is about trying to explain the common functionality that everyone can agree on.

> And I can see it being useful for sites like github
> which already have a cookie-based login.

What I'm concerned about is using the cookie jar. My Mac OS X laptop has 5 browsers installed, each with their own #@!*! cookie jar: Safari, Opera, Firefox, Camino, Google Chrome. How the hell is the git client going to be able to use those cookies in order to interact with a website that requires cookie authentication?

> Adapting the client to handle
> this case would not be too difficult (it would just mean keeping cookie
> state in a file between runs,

Saving our own cookie jar is easy, libcurl has some limited cookie jar support already built in. We just have to enable it.

> or even just pulling it out of the normal
> browser's cookie store).
See above, I don't think this will be very easy.
> And people whose client didn't do this would
> simply get an "access denied" response code.

And then they will email git ML or ask on #git why their git client can't speak to some random website... and its because they used "lynx" or yet-another-browser whose cookie jar format we can't read.

> Is there a technical reason not to allow it?

Not technical, but I want to reduce the amount of complexity that a conforming client has to deal with to reduce support costs for everyone involved.

I weakend the sections on cookies:
+ Authentication
+ --------------
....
+ Servers SHOULD NOT require HTTP cookies for the purposes of
+ authentication or access control.

and that's all we say on the matter. I took out the Servers MUST NOT line under session state.

-- 
Shawn.
Previous: Jeff KingNext: Jeff King
Message 13 of 46 in “Return of smart HTTP”
  1. 0/4 Return of smart HTTPShawn O. Pearce, Oct 9, 2009
  2. 1/4 Document the HTTP transport protocolShawn O. Pearce, Oct 9, 2009
  3. 2/4 Git-aware CGI to provide dumb HTTP transportShawn O. Pearce, Oct 9, 2009
  4. 3/4 Add smart-http options to upload-pack, receive-packShawn O. Pearce, Oct 9, 2009
  5. 4/4 Smart fetch and push over HTTP: server sideShawn O. Pearce, Oct 9, 2009
  6. J.H.Oct 9, 2009
  7. Sverre RabbelierOct 9, 2009
  8. Sverre RabbelierOct 9, 2009
  9. Alex BlewittOct 9, 2009
  10. Shawn O. PearceOct 15, 2009
  11. Jakub NarebskiOct 9, 2009
  12. Jeff KingOct 9, 2009
  13. Shawn O. PearceOct 15, 2009
  14. Jeff KingOct 15, 2009
  15. Junio C HamanoOct 9, 2009
  16. Antti-Juhani KaijanahoOct 10, 2009
  17. H. Peter AnvinOct 16, 2009
  18. Mike HommeyOct 16, 2009
  19. Shawn O. PearceOct 16, 2009
  20. Antti-Juhani KaijanahoOct 16, 2009
  21. Tay Ray ChuanApr 7, 2010
  22. Tay Ray ChuanApr 7, 2010
  23. (resend v2) Re: [RFC PATCH 1/4] Document the HTTP transport protocolTay Ray Chuan, Apr 7, 2010
  24. Junio C HamanoApr 7, 2010
  25. Tay Ray ChuanApr 8, 2010
  26. (resend v2) Re: [RFC PATCH 1/4] Document the HTTP transport protocolTay Ray Chuan, Apr 7, 2010
  27. Tay Ray ChuanOct 10, 2009
  28. Scott ChaconApr 6, 2010
  29. Junio C HamanoApr 6, 2010
  30. 00/14 document edits to original http protocol documentationTay Ray Chuan, Sep 10, 2013
  31. 01/14 Document the HTTP transport protocolTay Ray Chuan, Sep 10, 2013
  32. 02/14 normalize indentation with protcol-common.txtTay Ray Chuan, Sep 10, 2013
  33. 03/14 capitalize key words according to RFC 2119Tay Ray Chuan, Sep 10, 2013
  34. 04/14 normalize rules with RFC 5234Tay Ray Chuan, Sep 10, 2013
  35. 05/14 drop rules, etc. common to the pack protocolTay Ray Chuan, Sep 10, 2013
  36. 06/14 reword behaviour on missing repository or objectsTay Ray Chuan, Sep 10, 2013
  37. 07/14 weaken specification over cookies for authenticationTay Ray Chuan, Sep 10, 2013
  38. 08/14 mention different variations around $GIT_URLTay Ray Chuan, Sep 10, 2013
  39. 09/14 reduce ambiguity over '?' in $GIT_URL for dumb clientsTay Ray Chuan, Sep 10, 2013
  40. 10/14 fix example request/responsesTay Ray Chuan, Sep 10, 2013
  41. 11/14 be clearer in place of 'remote repository' phraseTay Ray Chuan, Sep 10, 2013
  42. 12/14 reduce confusion over smart server response behaviourTay Ray Chuan, Sep 10, 2013
  43. 13/14 shift dumb server response detailsTay Ray Chuan, Sep 10, 2013
  44. 14/14 mention effect of "allow-tip-sha1-in-want" capability on git-upload-packTay Ray Chuan, Sep 10, 2013
  45. 1/4 Document the HTTP transport protocolScott Chacon, Apr 6, 2010
  46. Junio C HamanoApr 6, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.