git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git remote origin leaks user access token

From
Jeff King <peff@peff.net>
Date
Jul 1, 2024, 18:35 UTC
Message-ID
<20240701183515.GF3199@coredump.intra.peff.net>
In-Reply-To
<ZoLY_yxpQBjmp8O3@tapette.crustytoothpaste.net>
On Mon, Jul 01, 2024 at 04:27:43PM +0000, brian m. carlson wrote:
Show 7 quoted lines
> I do want to point out that several people, not just me, have worked
> together to make using a credential helper as easy and robust as
> possible.  I mention this not to contradict Jonathan, who I think is
> also trying to help in this regard, but mostly to mention that as a
> project we've been trying to gently nudge people into doing the more
> secure thing.  If people have further suggestions on how to make this
> easier for users in the future, I'm very eager to hear them.

One thing we could do is refuse to store credentials in plaintext config. That helps people who aren't aware of the recommendations you mentioned end up more secure (though at the expense of convenience, as subsequent fetches won't work if you don't have a credential helper set up).

Some old discussion and possible patches here if anybody wants to pick up the topic:

  https://lore.kernel.org/git/nycvar.QRO.7.76.6.1905172121130.46@tvgsbejvaqbjf.bet/
-Peff
Previous: brian m. carlsonNext: H. Peter Anvin
Message 3 of 6 in “Re: Git remote origin leaks user access token”
  1. Jonathan NiederJul 1, 2024
  2. brian m. carlsonJul 1, 2024
  3. Jeff KingJul 1, 2024
  4. H. Peter AnvinJul 2, 2024
  5. Jeff KingJul 2, 2024
  6. Junio C HamanoJul 1, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.