git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: OAuth2 support in git?

From
Jeff King <peff@peff.net>
Date
Jun 18, 2018, 21:26 UTC
Message-ID
<20180618212614.GA2504@sigill.intra.peff.net>
In-Reply-To
<xmqqo9g8xf9k.fsf@gitster-ct.c.googlers.com>
On Mon, Jun 18, 2018 at 08:53:27AM -0700, Junio C Hamano wrote:
Show 18 quoted lines
> > Yeah, that will work for some cases. A few places it might not:
> >
> >  - some people may want to provide this only in response to a 401
> >
> >  - some tokens may need to be refreshed, which would require interacting
> >    with a credential helper to do the rest of the oauth conversation
> >
> >  - there's no good way to hide your token in secure storage (versus
> >    sticking it on the command-line or in a config file).
> 
> And all of these three are what you get for free by building on the
> credential helper framework, after extending it a bit so that the
> filled credential structure can tell the http code to show it to the
> other side as a bearer token, not a password or password hash.  The
> helper is asked to supply the auth material only after 401, which
> covers both the first and the second points, and then keeping the
> auth material in-core (e.g. cache--daemon) would be more secure
> which covers the third point.  Am I following you correctly?
Yes, exactly.

Even if the credential protocol itself doesn't learn about this feature, even a config option for "treat password as token to send via bearer" would help. The "how" of sending the token isn't secret, just the token itself. So everything else can just pretend it's a password (it's a little funny because I think there isn't a matching username, but you could probably get by with an empty one).

That's all just off the top of my head without digging back into the code, nor running any experiments, of course. There may be some gotchas. :)

-Peff
Previous: Junio C HamanoNext: Christian Halstrick
Message 10 of 12 in “OAuth2 support in git?”
  1. Christian HalstrickJun 14, 2018
  2. brian m. carlsonJun 14, 2018
  3. Jeff KingJun 14, 2018
  4. Randall S. BeckerJun 14, 2018
  5. Jeff KingJun 14, 2018
  6. brian m. carlsonJun 14, 2018
  7. Johannes SchindelinJun 17, 2018
  8. Jeff KingJun 18, 2018
  9. Junio C HamanoJun 18, 2018
  10. Jeff KingJun 18, 2018
  11. Christian HalstrickJun 19, 2018
  12. Jeff KingJun 19, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.