git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Add ERR support to smart HTTP

From
Jakub Narebski <jnareb@gmail.com>
Date
Sep 6, 2010, 16:31 UTC
Message-ID
<201009061832.00512.jnareb@gmail.com>
In-Reply-To
<AANLkTi=jqpspQvz6--CGfVEpP8raD7RpNGgMs6KabXfS@mail.gmail.com>
Sitaram Chamarty wrote:
> On Mon, Sep 6, 2010 at 2:19 PM, Jakub Narebski <jnareb@gmail.com> wrote:
Show 19 quoted lines
> > Nevertheless I think it would be a good idea to make *client* more
> > accepting, which means:
> > 1. Printing full HTTP status, and not only HTTP return / error code;
> >   perhaps only if it is non-standard, and perhaps only in --verbose
> >   mode.
> > 2. If message body contains ERR line, print error message even if the
> >   HTTP status was other than "200 OK".  To be "generous in what you
> >   receive" (well, kind of).
> > 3. In verbose mode, if body of HTTP error message (not "HTTP OK")
> >   exists and does not contain ERR line (e.g. an error from web server),
> >   print it in full (perhaps indented).
> >
> > I think that neither of the above would lead to leaking sensitive
> > information.
> 
> I didn't understand this bit about leaking info.  If the bits are
> coming into my machine I know what they are anyway (or am able to find
> out easily enough, even if git itself isn't showing them to me).
> Where's the leak?

I meant here that programs (including git) do not provide full details about error condition, especially if it has to do womething with authentication, to avoid leaking sensitive information (like e.g. saying that username + password combination is invalid, instead of telling which one is wrong, to avoid disclosing usernames).

-- 
Jakub Narebski
Poland
Previous: Sitaram ChamartyNext: Jonathan Nieder
Message 17 of 18 in “Add ERR support to smart HTTP”
  1. Add ERR support to smart HTTPIlari Liusvaara, Sep 5, 2010
  2. Jonathan NiederSep 5, 2010
  3. Ilari LiusvaaraSep 5, 2010
  4. Ævar Arnfjörð BjarmasonSep 5, 2010
  5. Ilari LiusvaaraSep 5, 2010
  6. Jakub NarebskiSep 5, 2010
  7. Sitaram ChamartySep 6, 2010
  8. Sitaram ChamartySep 6, 2010
  9. Ævar Arnfjörð BjarmasonSep 6, 2010
  10. Jakub NarebskiSep 6, 2010
  11. Joshua JuranSep 6, 2010
  12. Shawn O. PearceSep 6, 2010
  13. Sitaram ChamartySep 6, 2010
  14. Shawn O. PearceSep 6, 2010
  15. Sitaram ChamartySep 8, 2010
  16. Sitaram ChamartySep 6, 2010
  17. Jakub NarebskiSep 6, 2010
  18. Jonathan NiederSep 5, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.