git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Git over HTTP; have flexible SASL authentication

From
RRRick van Rein <rick@openfortress.nl>
Date
Jan 27, 2023, 16:34 UTC
Message-ID
<20230127163434.GA784@openfortress.nl>
Hello,

Git providers are inventing proprietary extensions to HTTP authentication for Git. It seems smarter to use SASL for this purpose, possibly allowing the client a choice and authentication ringback to the client's own domain.

I wrote an Internet Draft to allow just that, and we implemented it for Apache, Nginx and FireFox. I would love to learn if this list considers it a sensible extensions to Git. https://datatracker.ietf.org/doc/html/draft-vanrein-httpauth-sasl

If you think this is useful, it would be wonderful to mention that on the HTTP WorkGroup list as well, because they are now considering HTTP-SASL for adoption, a formal requisite to send "Authorization: SASL" headers. https://datatracker.ietf.org/wg/httpbis/about/

Thanks!

Rick van Rein InternetWide.org

Apache  :- https://gitlab.com/arpa2/apachemod/-/tree/master/arpa2_sasl
           https://gitlab.com/arpa2/apachemod/-/tree/master/arpa2_diasasl
Nginx   :- https://github.com/stef/ngx_http_auth_sasl_module
FireFox :- https://gitlab.com/arpa2/http_sasl_client
Next: Junio C Hamano
Message 1 of 6 in “Git over HTTP; have flexible SASL authentication”
  1. Rick van ReinJan 27, 2023
  2. Junio C HamanoJan 27, 2023
  3. Jeff KingFeb 1, 2023
  4. Matthew John CheethamFeb 1, 2023
  5. Rick van ReinFeb 4, 2023
  6. Junio C HamanoFeb 6, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.