git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH][v2] http authentication via prompts (with correct line lengths)

From
Mike Gaffney <mr.gaffo@gmail.com>
Date
Mar 10, 2009, 03:25 UTC
Message-ID
<49B5DDA6.8070108@gmail.com>
In-Reply-To
<alpine.DEB.1.00.0903100143550.6358@intel-tinevez-2-302>
I guess it makes sense to split the config out into two patches. I wanted both to help with automated builds, and as it's a read only account I wasn't worried about someone reading the password. I'm not very impressed with the permissions on the .netrc file actually providing security so I can see not allowing the password in the config either. In my system at work, we have shared machines but all developers have root access, so file permissions don't really secure anything for us. It's also why we can't really use keys (there is no way to enforce that a key is secured afaik).
I wanted to do a remote specific config as well but a global works well in many environments where your push repo is under http as you don't keep having to configure it. I also couldn't see a good way to do a remote specific config without changing the remote struct (which seemd like putting specific in a general). I would love some advice on this and where to put it.
I can see your security points but I would argue that if that's what we are worried about then we should not allow the netrc file at all. I added notes in the config documentation about this. I'm open to discussion on this point.
Johannes Schindelin wrote:
Show 15 quoted lines
> Hi,
> 
> On Mon, 9 Mar 2009, Junio C Hamano wrote:
> 
>> It appears that none of the issues I raised in my response to your 
>> earlier round was addressed in this patch, except for the line 
>> rewrapping of the proposed commit log message.
> 
> AFAICT my concerns were not addressed either: misleading subject unless 
> the patch is split into two, remote specific config variable instead of 
> global one, security issues.
> 
> Ciao,
> Dscho
> 
-- 
-Mike Gaffney (http://rdocul.us)
Previous: Johannes SchindelinNext: Johannes Schindelin
Message 4 of 20 in “[v2] http authentication via prompts (with correct line lengths)”
  1. [v2] http authentication via prompts (with correct line lengths)Mike Gaffney, Mar 10, 2009
  2. Junio C HamanoMar 10, 2009
  3. Johannes SchindelinMar 10, 2009
  4. Mike GaffneyMar 10, 2009
  5. Johannes SchindelinMar 10, 2009
  6. Mike GaffneyMar 10, 2009
  7. Mike GaffneyMar 10, 2009
  8. Junio C HamanoMar 10, 2009
  9. Daniel StenbergMar 10, 2009
  10. Junio C HamanoMar 10, 2009
  11. Mike RalphsonMar 12, 2009
  12. Daniel StenbergMar 12, 2009
  13. Mike RalphsonMar 12, 2009
  14. Daniel StenbergMar 12, 2009
  15. Junio C HamanoMar 13, 2009
  16. Daniel StenbergMar 13, 2009
  17. Mike RalphsonMar 13, 2009
  18. Junio C HamanoMar 14, 2009
  19. Mike GaffneyMar 13, 2009
  20. Junio C HamanoMar 14, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.