git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git-http-backend and Authenticated Pushes

From
Ryan Phillips <ryan@trolocsis.com>
Date
Mar 10, 2010, 02:13 UTC
Message-ID
<46a47f951003091813p768fdb58v454f2553a8b6ed8@mail.gmail.com>
In-Reply-To
<20100309192726.GA12461@spearce.org>
On Tue, Mar 9, 2010 at 1:27 PM, Shawn O. Pearce <spearce@spearce.org> wrote:
Show 26 quoted lines
> Ryan Phillips <ryan@trolocsis.com> wrote:
>> I'm trying to follow the git-http-backend man page on setting up
>> authenticated pushes to my apache server. Pulls work fine, and fully
>> authenticated pushes work fine. However, when I try and setup
>> anonymous pulls and authenticated pushes the push fails.
>>
>> I believe the culprit is this 403 error:
>>
>> 192.168.1.1 - - [09/Mar/2010:09:01:43 -0800] "GET
>> /git/test.git/info/refs?service=git-receive-pack HTTP/1.1" 403 - "-"
>> "git/1.7.0.2.dirty"
>
> Ugh.  Looks like I didn't design this thing right.
>
> The backend wants you to be authenticated before it will service
> the git-receive-pack advertisement.  Even though its the same
> data as the git-upload-pack advertisement (but slightly different
> capability strings).
>
> Maybe we should consider doing something like this patch so that
> the advertisement under info/refs?service=git-receive-pack can be
> sent without needing authentication.  My only hesitation is this
> makes it harder for the client to setup the authentication before
> it needs to transmit the pack file, which may mean it needs to send
> the pack twice.
>
Thank you everyone for your response.
Shawn: That patch does fix the issue for now.

Regards, Ryan

Previous: Shawn O. Pearce
Message 6 of 6 in “git-http-backend and Authenticated Pushes”
  1. Ryan PhillipsMar 9, 2010
  2. Antonio García DomínguezMar 9, 2010
  3. BJ HargraveMar 9, 2010
  4. Antonio García DomínguezMar 9, 2010
  5. Shawn O. PearceMar 9, 2010
  6. Ryan PhillipsMar 10, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.