git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 6/8] t: test http access to "half-auth" repositories

From
Jeff King <peff@peff.net>
Date
Aug 27, 2012, 13:25 UTC
Message-ID
<20120827132553.GF17375@sigill.intra.peff.net>
In-Reply-To
<20120827132145.GA17265@sigill.intra.peff.net>

Some sites set up http access to repositories such that fetching is anonymous and unauthenticated, but pushing is authenticated. While there are multiple ways to do this, the technique advertised in the git-http-backend manpage is to block access to locations matching "/git-receive-pack$".

Let's emulate that advice in our test setup, which makes it clear that this advice does not actually work.

Signed-off-by: Jeff King <peff@peff.net>
---
 t/lib-httpd/apache.conf |  7 +++++++
 t/t5541-http-push.sh    | 12 ++++++++++++
 t/t5551-http-fetch.sh   |  9 +++++++++
 3 files changed, 28 insertions(+)
diff --git a/t/lib-httpd/apache.conf b/t/lib-httpd/apache.conf
index c6a1a87..49d5d87 100644
--- a/t/lib-httpd/apache.conf
+++ b/t/lib-httpd/apache.conf
@@ -92,6 +92,13 @@ SSLEngine On
 	Require valid-user
 </Location>
 
+<LocationMatch "^/auth-push/.*/git-receive-pack$">
+	AuthType Basic
+	AuthName "git-auth"
+	AuthUserFile passwd
+	Require valid-user
+</LocationMatch>
+
 <IfDefine DAV>
 	LoadModule dav_module modules/mod_dav.so
 	LoadModule dav_fs_module modules/mod_dav_fs.so
diff --git a/t/t5541-http-push.sh b/t/t5541-http-push.sh
index eeb9932..9b1cd60 100755
--- a/t/t5541-http-push.sh
+++ b/t/t5541-http-push.sh
@@ -280,5 +280,17 @@ test_expect_success 'push over smart http with auth' '
 	test_cmp expect actual
 '
 
+test_expect_failure 'push to auth-only-for-push repo' '
+	cd "$ROOT_PATH/test_repo_clone" &&
+	echo push-half-auth >expect &&
+	test_commit push-half-auth &&
+	set_askpass user@host &&
+	git push "$HTTPD_URL"/auth-push/smart/test_repo.git &&
+	git --git-dir="$HTTPD_DOCUMENT_ROOT_PATH/test_repo.git" \
+		log -1 --format=%s >actual &&
+	expect_askpass both user@host &&
+	test_cmp expect actual
+'
+
 stop_httpd
 test_done
diff --git a/t/t5551-http-fetch.sh b/t/t5551-http-fetch.sh
index e653ae3..2db5c35 100755
--- a/t/t5551-http-fetch.sh
+++ b/t/t5551-http-fetch.sh
@@ -120,6 +120,15 @@ test_expect_success 'clone from password-protected repository' '
 	test_cmp expect actual
 '
 
+test_expect_success 'clone from auth-only-for-push repository' '
+	echo two >expect &&
+	set_askpass wrong &&
+	git clone --bare "$HTTPD_URL/auth-push/smart/repo.git" smart-noauth &&
+	expect_askpass none &&
+	git --git-dir=smart-noauth log -1 --format=%s >actual &&
+	test_cmp expect actual
+'
+
 test -n "$GIT_TEST_LONG" && test_set_prereq EXPENSIVE
 
 test_expect_success EXPENSIVE 'create 50,000 tags in the repo' '
-- 
1.7.11.5.10.g3c8125b
Previous: Jeff KingNext: Jeff King
Message 13 of 22 in “git no longer prompting for password”
  1. Iain PatonAug 24, 2012
  2. Jeff KingAug 24, 2012
  3. Jeff KingAug 25, 2012
  4. Iain PatonAug 26, 2012
  5. Jeff KingAug 26, 2012
  6. Iain PatonAug 26, 2012
  7. 0/8 fix password prompting for "half-auth" serversJeff King, Aug 27, 2012
  8. 1/8 t5550: put auth-required repo in auth/dumbJeff King, Aug 27, 2012
  9. 2/8 t5550: factor out http auth setupJeff King, Aug 27, 2012
  10. 3/8 t/lib-httpd: only route auth/dumb to dumb reposJeff King, Aug 27, 2012
  11. 4/8 t/lib-httpd: recognize */smart/* repos as smart-httpJeff King, Aug 27, 2012
  12. 5/8 t: test basic smart-http authenticationJeff King, Aug 27, 2012
  13. 6/8 t: test http access to "half-auth" repositoriesJeff King, Aug 27, 2012
  14. 7/8 http: factor out http error code handlingJeff King, Aug 27, 2012
  15. Junio C HamanoAug 28, 2012
  16. 8/8 http: prompt for credentials on failed POSTJeff King, Aug 27, 2012
  17. Junio C HamanoAug 27, 2012
  18. Jeff KingAug 27, 2012
  19. Junio C HamanoAug 27, 2012
  20. Junio C HamanoAug 27, 2012
  21. Iain PatonAug 27, 2012
  22. BJ HargraveAug 27, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.