git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC/PATCH] http-push: don't always prompt for password (Was Re: [ANNOUNCE] Git 1.7.8.rc0)

From
Michael J Gruber <git@drmicha.warpmail.net>
Date
Nov 2, 2011, 14:08 UTC
Message-ID
<4EB14EC8.2070400@drmicha.warpmail.net>
In-Reply-To
<4EB104EA.2040001@atlas-elektronik.com>
Stefan Näwe venit, vidit, dixit 02.11.2011 09:52:
Show 70 quoted lines
> Am 01.11.2011 19:12, schrieb Junio C Hamano:
>>
>> There are only handful of commits that even remotely touch http related
>> codepath between v1.7.7 and v1.7.8-rc0:
>>
>>   * deba493 http_init: accept separate URL parameter
>>
>>   This could change the URL string given to http_auth_init().
>>
>>   * 070b4dd http: use hostname in credential description
>>
>>   This only changes the prompt string; as far as I understand it, the
>>   condition the password is prompted in the callsites of git_getpass()
>>   has not changed.
>>
>>   * 6cdf022 remote-curl: Fix warning after HTTP failure
>>   * be22d92 http: avoid empty error messages for some curl errors
>>   * 8abc508 http: remove extra newline in error message
>>   * 8d677ed http: retry authentication failures for all http requests
>>   * 28d0c10 remote-curl: don't retry auth failures with dumb protocol
>>
>>   These shouldn't affect anything wrt prompting, unless you are somehow
>>   internally reauthenticating.
>>
>> Could you try reverting deba493 and retest, and then if the behaviour is
>> the same "need ENTER", further revert 070b4dd and retest?
> 
> I did a little more testing.
> This WIP makes it work for me (i.e. "need ENTER" is gone, works with
> and without .netrc, with 'https://host/repo.git' and 
> 'https://user@host...' URL). Needs testing, of course.
> 
> ---8<---8<---8<---8<---8<---8<---8<---8<---8<---8<---8<---8<---8<---
> diff --git a/http.c b/http.c
> index a4bc770..008ad72 100644
> --- a/http.c
> +++ b/http.c
> @@ -279,8 +279,6 @@ static CURL *get_curl_handle(void)
>         curl_easy_setopt(result, CURLOPT_HTTPAUTH, CURLAUTH_ANY);
>  #endif
> 
> -       init_curl_http_auth(result);
> -
>         if (ssl_cert != NULL)
>                 curl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);
>         if (has_cert_password())
> @@ -846,7 +844,7 @@ static int http_request(const char *url, void *result, int target, int options)
>                 else if (missing_target(&results))
>                         ret = HTTP_MISSING_TARGET;
>                 else if (results.http_code == 401) {
> -                       if (user_name) {
> +                       if (user_name && user_pass) {
>                                 ret = HTTP_NOAUTH;
>                         } else {
>                                 /*
> @@ -855,7 +853,8 @@ static int http_request(const char *url, void *result, int target, int options)
>                                  * but that is non-portable.  Using git_getpass() can at least be stubbed
>                                  * on other platforms with a different implementation if/when necessary.
>                                  */
> -                               user_name = xstrdup(git_getpass_with_description("Username", description));
> +                               if (!user_name)
> +                                       user_name = xstrdup(git_getpass_with_description("Username", description));
>                                 init_curl_http_auth(slot->curl);
>                                 ret = HTTP_REAUTH;
>                         }
> ---8<---8<---8<---8<---8<---8<---8<---8<---8<---8<---8<---8<---8<---
> 
> 
> Regards,
>   Stefan
Thanks!
Tested-by: Michael J Gruber <git@drmicha.warpmail.net>

More specifically, I ran our test suite (next plus Stefan's patch), and tested

https://user@host with .netrc and with askpass https://host with .netrc

The latter fails with askpass because we ask Password for 'host' and not Password for 'user@host' but that is true both with and without the patch. (I thought we had changed that, but I guess it's cooking.)

Michael
Previous: Stefan NäweNext: Junio C Hamano
Message 17 of 26 in “[ANNOUNCE] Git 1.7.8.rc0”
  1. Junio C HamanoOct 31, 2011
  2. Stefan NäweOct 31, 2011
  3. Junio C HamanoOct 31, 2011
  4. Stefan NäweNov 1, 2011
  5. Junio C HamanoNov 1, 2011
  6. Jeff KingNov 1, 2011
  7. Stefan NaeweNov 1, 2011
  8. Stefan NaeweNov 1, 2011
  9. Michael J GruberNov 2, 2011
  10. Jeff KingNov 2, 2011
  11. Jeff KingNov 2, 2011
  12. Junio C HamanoNov 2, 2011
  13. Jeff KingNov 2, 2011
  14. Junio C HamanoNov 3, 2011
  15. Stefan NaeweNov 1, 2011
  16. http-push: don't always prompt for password (Was Re: [ANNOUNCE] Git 1.7.8.rc0)Stefan Näwe, Nov 2, 2011
  17. Michael J GruberNov 2, 2011
  18. Junio C HamanoNov 2, 2011
  19. Jeff KingNov 2, 2011
  20. Junio C HamanoNov 2, 2011
  21. http-push: don't always prompt for passwordStefan Naewe, Nov 4, 2011
  22. Junio C HamanoNov 4, 2011
  23. Jeff KingNov 4, 2011
  24. Junio C HamanoNov 4, 2011
  25. Stefan NaeweNov 4, 2011
  26. Junio C HamanoNov 5, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.