git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git no longer prompting for password

From
IPIain Paton <ipaton0@gmail.com>
Date
Aug 26, 2012, 14:18 UTC
Message-ID
<503A3023.6000103@gmail.com>
In-Reply-To
<20120826101341.GA12566@sigill.intra.peff.net>
On 26/08/12 11:13, Jeff King wrote:
> Yeah, I'm surprised it took this long to come up, too. Perhaps most
> people just do anonymous http, and then rely on ssh for pushing to
> achieve the same effect. Or maybe my analysis of the problem is wrong.
> :)

I'd be using ssh to push too, but the simple fact is that the http way works through a proxy and so essentially works from anywhere. The same isn't true for ssh or git protocols. Well that's my reason anyway :)

> Yeah, I think that will work. It feels a little weird and hacky. E.g.,

Yeah, it does. I couldn't find a simple way though, most stuff like LocationMatch specifically excludes the query string which makes it rather more difficult.

> I don't know enough about Apache to know off-hand if there is a cleaner
> way. I'll investigate a bit more before doing my documentation patch.

I'm not an apache expert either. What I could find was using mod_rewrite to set an env var based on something in the query string, but not actually do any rewrite. Then looking at how to check the env var and do something based on that got me the example of simply using If with an expression to match directly on the query string.

> I think that would be cleaner. It would be even nicer if you could
> really just match "service=" as a query parameter, but I don't know that
> apache parses that at all. I also don't know if Apache does any
> canonicalization of the QUERY_STRING. When matching, you'd want to make
>From what I can tell apache really doesn't care much about the query string 

at all, it seems to just pass it through unless you start messing with it using mod_rewrite, but even then you're still regex based. I couldn't find anything that parsed out individual parameters. Of course I could just be looking in all the wrong places :)

> sure there is no way of a client sneaking in a parameter that git would
> understand to mean a push, but that your pattern would not notice (so,
> e.g., just matching "git-receive-pack$" would not be sufficient, as I

yep, and matching on THE_REQUEST gets you the whole string, including the HTTP/1.1 on the end. I tried putting the $ on the end of the regex and it didn't work. It should be possible to combine the original regex from the LocationMatch example and something like /[?&]service=git-receive-pack/ though, which should make it somewhat safer.

> No problem. I'll probably be a day or two on the patches, as the http
> tests are in need of some refactoring before adding more tests. But in
> the meantime, I think your config change is a sane work-around.

Works-For-Me is all I need right now :) I'll be interested if you come up with something better though.

Iain
Previous: Jeff KingNext: Jeff King
Message 6 of 22 in “git no longer prompting for password”
  1. Iain PatonAug 24, 2012
  2. Jeff KingAug 24, 2012
  3. Jeff KingAug 25, 2012
  4. Iain PatonAug 26, 2012
  5. Jeff KingAug 26, 2012
  6. Iain PatonAug 26, 2012
  7. 0/8 fix password prompting for "half-auth" serversJeff King, Aug 27, 2012
  8. 1/8 t5550: put auth-required repo in auth/dumbJeff King, Aug 27, 2012
  9. 2/8 t5550: factor out http auth setupJeff King, Aug 27, 2012
  10. 3/8 t/lib-httpd: only route auth/dumb to dumb reposJeff King, Aug 27, 2012
  11. 4/8 t/lib-httpd: recognize */smart/* repos as smart-httpJeff King, Aug 27, 2012
  12. 5/8 t: test basic smart-http authenticationJeff King, Aug 27, 2012
  13. 6/8 t: test http access to "half-auth" repositoriesJeff King, Aug 27, 2012
  14. 7/8 http: factor out http error code handlingJeff King, Aug 27, 2012
  15. Junio C HamanoAug 28, 2012
  16. 8/8 http: prompt for credentials on failed POSTJeff King, Aug 27, 2012
  17. Junio C HamanoAug 27, 2012
  18. Jeff KingAug 27, 2012
  19. Junio C HamanoAug 27, 2012
  20. Junio C HamanoAug 27, 2012
  21. Iain PatonAug 27, 2012
  22. BJ HargraveAug 27, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.