git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] http-push: don't always prompt for password

From
Jeff King <peff@peff.net>
Date
Nov 4, 2011, 17:43 UTC
Message-ID
<20111104174303.GA22568@sigill.intra.peff.net>
In-Reply-To
<7vlirvdeb2.fsf@alter.siamese.dyndns.org>
On Fri, Nov 04, 2011 at 09:48:17AM -0700, Junio C Hamano wrote:
Show 18 quoted lines
> Stefan Naewe <stefan.naewe@gmail.com> writes:
> 
> > http-push prompts for a password when the URL is set as
> > 'https://user@host/repo' even though there is one set
> > in ~/.netrc. Pressing ENTER at the password prompt succeeds
> > then, but is a annoying and makes it almost useless
> > in a shell script, e.g.
> >
> > Signed-off-by: Stefan Naewe <stefan.naewe@gmail.com>
> > ---
> 
> Thanks.
> 
> With this the only callsite of init_curl_http_auth() becomes the one after
> we get the 401 response, and this caller makes sure that user_name is not
> NULL.
> 
> Do we still want "if (user_name)" inside init_curl_http_auth()?

Since we now only call init_curl_http_auth when we know we need auth, I think it would make more sense to just move the user_name asking there, too, like:

  static void init_curl_http_auth(CURL *result)
  {
          struct strbuf up = STRBUF_INIT;
          if (!user_name)
                  user_name = xstrdup(git_getpass_with_description("Username", description);
          if (!user_pass)
                  user_pass = xstrdup(git_getpass_with_description("Password", description);
          strbuf_addf(&up, "%s:%s", user_name, user_pass);
          curl_easy_setopt(result, CURLOPT_USERPWD, strbuf_detach(&up, NULL));
  }

And then it's easy to swap out the asking for credential_fill() when it becomes available. But I admit I don't care that much now, as I'll just end up doing that refactoring later with my credential patches anyway.

> I tried to rewrite the proposed commit log message to describe the real
> issue, and here is what I came up with:
Your description looks accurate to me.
Show 6 quoted lines
> What is somewhat troubling is that after analyzing the root cause of the
> issue, I am wondering if a more correct fix is to remove the user@ part
> from the URL (in other words, document that a URL with an embedded
> username will ask for password upfront, and tell the users that if they
> have netrc entries or if they are accessing a resource that does not
> require authentication, they should omit the username from the URL).

It's tempting, because the non-netrc case is the common one, and we are dropping the round-trip avoidance for those people. I'm just not sure that it's going to be obvious to users that they need to drop the user@ portion from their URL when using netrc. That seems like a bizarre requirement from the user's POV, even if we do document it.

-Peff
Previous: Junio C HamanoNext: Junio C Hamano
Message 23 of 26 in “[ANNOUNCE] Git 1.7.8.rc0”
  1. Junio C HamanoOct 31, 2011
  2. Stefan NäweOct 31, 2011
  3. Junio C HamanoOct 31, 2011
  4. Stefan NäweNov 1, 2011
  5. Junio C HamanoNov 1, 2011
  6. Jeff KingNov 1, 2011
  7. Stefan NaeweNov 1, 2011
  8. Stefan NaeweNov 1, 2011
  9. Michael J GruberNov 2, 2011
  10. Jeff KingNov 2, 2011
  11. Jeff KingNov 2, 2011
  12. Junio C HamanoNov 2, 2011
  13. Jeff KingNov 2, 2011
  14. Junio C HamanoNov 3, 2011
  15. Stefan NaeweNov 1, 2011
  16. http-push: don't always prompt for password (Was Re: [ANNOUNCE] Git 1.7.8.rc0)Stefan Näwe, Nov 2, 2011
  17. Michael J GruberNov 2, 2011
  18. Junio C HamanoNov 2, 2011
  19. Jeff KingNov 2, 2011
  20. Junio C HamanoNov 2, 2011
  21. http-push: don't always prompt for passwordStefan Naewe, Nov 4, 2011
  22. Junio C HamanoNov 4, 2011
  23. Jeff KingNov 4, 2011
  24. Junio C HamanoNov 4, 2011
  25. Stefan NaeweNov 4, 2011
  26. Junio C HamanoNov 5, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.