git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 1/2] http: restrict auth methods to what the server advertises

From
Jeff King <peff@peff.net>
Date
Feb 22, 2017, 23:34 UTC
Message-ID
<20170222233436.l5c3ya53cl7y5x7z@sigill.intra.peff.net>
In-Reply-To
<20170222233333.dx5lknw4fpopu5hy@sigill.intra.peff.net>

By default, we tell curl to use CURLAUTH_ANY, which does not limit its set of auth methods. However, this results in an extra round-trip to the server when authentication is required. After we've fed the credential to curl, it wants to probe the server to find its list of available methods before sending an Authorization header.

We can shortcut this by limiting our http_auth_methods by what the server told us it supports. In some cases (such as when the server only supports Basic), that lets curl skip the extra probe request.

The end result should look the same to the user, but you can use GIT_TRACE_CURL to verify the sequence of requests:

  GIT_TRACE_CURL=1 \
  git ls-remote https://example.com/repo.git \
  2>&1 >/dev/null |
  egrep '(Send|Recv) header: (GET|HTTP|Auth)'

Before this patch, hitting a Basic-only server like github.com results in:

  Send header: GET /repo.git/info/refs?service=git-upload-pack HTTP/1.1
  Recv header: HTTP/1.1 401 Authorization Required
  Send header: GET /repo.git/info/refs?service=git-upload-pack HTTP/1.1
  Recv header: HTTP/1.1 401 Authorization Required
  Send header: GET /repo.git/info/refs?service=git-upload-pack HTTP/1.1
  Send header: Authorization: Basic <redacted>
  Recv header: HTTP/1.1 200 OK
And after:
  Send header: GET /repo.git/info/refs?service=git-upload-pack HTTP/1.1
  Recv header: HTTP/1.1 401 Authorization Required
  Send header: GET /repo.git/info/refs?service=git-upload-pack HTTP/1.1
  Send header: Authorization: Basic <redacted>
  Recv header: HTTP/1.1 200 OK
The possible downsides are:
  - This only helps for a Basic-only server; for a server
    with multiple auth options, curl may still send a probe
    request to see which ones are available (IOW, there's no
    way to say "don't probe, I already know what the server
    will say").
  - The http_auth_methods variable is global, so this will
    apply to all further requests. That's acceptable for
    Git's usage of curl, though, which also treats the
    credentials as global. I.e., in any given program
    invocation we hit only one conceptual server (we may be
    redirected at the outset, but in that case that's whose
    auth_avail field we'd see).
Signed-off-by: Jeff King <peff@peff.net>
---
 http.c | 2 ++
 1 file changed, 2 insertions(+)
diff --git a/http.c b/http.c
index 90a1c0f11..a05609766 100644
--- a/http.c
+++ b/http.c
@@ -1347,6 +1347,8 @@ static int handle_curl_result(struct slot_results *results)
 		} else {
 #ifdef LIBCURL_CAN_HANDLE_AUTH_ANY
 			http_auth_methods &= ~CURLAUTH_GSSNEGOTIATE;
+			if (results->auth_avail)
+				http_auth_methods &= results->auth_avail;
 #endif
 			return HTTP_REAUTH;
 		}
-- 
2.12.0.rc2.597.g959f68882
Previous: Johannes Schindelin
Message 38 of 38 in “http(s): automatically try NTLM authentication first”
  1. http(s): automatically try NTLM authentication firstDavid Turner, Feb 22, 2017
  2. Junio C HamanoFeb 22, 2017
  3. David TurnerFeb 22, 2017
  4. Junio C HamanoFeb 22, 2017
  5. Jeff KingFeb 22, 2017
  6. Johannes SchindelinFeb 23, 2017
  7. Junio C HamanoFeb 23, 2017
  8. Jeff KingFeb 23, 2017
  9. Junio C HamanoFeb 23, 2017
  10. Jeff KingFeb 23, 2017
  11. Johannes SchindelinFeb 25, 2017
  12. brian m. carlsonFeb 22, 2017
  13. Jeff KingFeb 22, 2017
  14. Junio C HamanoFeb 23, 2017
  15. Junio C HamanoFeb 23, 2017
  16. Jeff KingFeb 23, 2017
  17. David TurnerFeb 23, 2017
  18. brian m. carlsonFeb 23, 2017
  19. Mantas MikulėnasFeb 23, 2017
  20. Jeff KingFeb 22, 2017
  21. Junio C HamanoFeb 22, 2017
  22. Jeff KingFeb 22, 2017
  23. Junio C HamanoFeb 22, 2017
  24. Jeff KingFeb 22, 2017
  25. Junio C HamanoFeb 22, 2017
  26. Jeff KingFeb 22, 2017
  27. 2/2 http: add an "auto" mode for http.emptyauthJeff King, Feb 22, 2017
  28. David TurnerFeb 23, 2017
  29. Jeff KingFeb 23, 2017
  30. David TurnerFeb 23, 2017
  31. Jeff KingFeb 23, 2017
  32. David TurnerFeb 23, 2017
  33. Johannes SchindelinFeb 25, 2017
  34. Jeff KingFeb 25, 2017
  35. http: add an "auto" mode for http.emptyauthJeff King, Feb 25, 2017
  36. Junio C HamanoFeb 27, 2017
  37. Johannes SchindelinFeb 28, 2017
  38. 1/2 http: restrict auth methods to what the server advertisesJeff King, Feb 22, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.