git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: OAuth2 support in git?

From
Jeff King <peff@peff.net>
Date
Jun 18, 2018, 04:17 UTC
Message-ID
<20180618041713.GA31125@sigill.intra.peff.net>
In-Reply-To
<nycvar.QRO.7.76.6.1806171335480.77@tvgsbejvaqbjf.bet>
On Sun, Jun 17, 2018 at 01:37:24PM +0200, Johannes Schindelin wrote:
Show 8 quoted lines
> > If it's just a custom Authorization header, we should be able to support
> > it with existing curl versions without _too_ much effort.
> 
> Indeed. Because it is already implemented:
> 
> 	git -c http.extraheader="Authorization: Bearer ..." ...
> 
> To make this a *little* safer, you can use http.<URL>.extraheader.
Yeah, that will work for some cases. A few places it might not:
 - some people may want to provide this only in response to a 401
 - some tokens may need to be refreshed, which would require interacting
   with a credential helper to do the rest of the oauth conversation
 - there's no good way to hide your token in secure storage (versus
   sticking it on the command-line or in a config file).
-Peff
Previous: Johannes SchindelinNext: Junio C Hamano
Message 8 of 12 in “OAuth2 support in git?”
  1. Christian HalstrickJun 14, 2018
  2. brian m. carlsonJun 14, 2018
  3. Jeff KingJun 14, 2018
  4. Randall S. BeckerJun 14, 2018
  5. Jeff KingJun 14, 2018
  6. brian m. carlsonJun 14, 2018
  7. Johannes SchindelinJun 17, 2018
  8. Jeff KingJun 18, 2018
  9. Junio C HamanoJun 18, 2018
  10. Jeff KingJun 18, 2018
  11. Christian HalstrickJun 19, 2018
  12. Jeff KingJun 19, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.