git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH v1] http: add http.keepRejectedCredentials config

From
Lars Schneider <larsxschneider@gmail.com>
Date
Jun 8, 2018, 03:15 UTC
Message-ID
<46F82119-D185-4B41-828B-FC92709CFCDA@gmail.com>
In-Reply-To
<20180604185551.GA4296@sigill.intra.peff.net>
Show 19 quoted lines
> On 04 Jun 2018, at 11:55, Jeff King <peff@peff.net> wrote:
> 
> On Mon, Jun 04, 2018 at 12:18:59PM -0400, Martin-Louis Bright wrote:
> 
>> Why must the credentials must be deleted after receiving the 401 (or
>> any) error? What's the rationale for this?
> 
> Because Git only tries a single credential per invocation. So if a
> helper provides one, it doesn't prompt. If you get a 401 and then the
> program aborts, invoking it again is just going to try the same
> credential over and over. Dropping the credential from the helper breaks
> out of that loop.
> 
> In fact, this patch probably should give the user some advice in that
> regard (either in the documentation, or as a warning when we skip the
> rejection). If you _do_ have a bogus credential and set the new option,
> you'd need to reject it manually (you can do it with "git credential
> reject", but it's probably easier to just unset the option temporarily
> and re-invoke the original command).
I like the advice idea very much!
How about this?

$ git fetch hint: Git has stored invalid credentials. hint: Reject them with 'git credential reject' or hint: disable the Git config 'http.keepRejectedCredentials'. remote: Invalid username or password. fatal: Authentication failed for 'https://server.com/myrepo.git/'

I am not really sure about the grammar :-)

Thanks, Lars

Previous: Jeff KingNext: Jeff King
Message 5 of 6 in “http: add http.keepRejectedCredentials config”
  1. http: add http.keepRejectedCredentials configlars.schneider@autodesk.com, Jun 4, 2018
  2. Jeff KingJun 4, 2018
  3. Martin-Louis BrightJun 4, 2018
  4. Jeff KingJun 4, 2018
  5. Lars SchneiderJun 8, 2018
  6. Jeff KingJun 8, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.