git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 3/3] t5563: add tests for http.emptyAuth with Negotiate

From
Matthew John Cheetham via GitGitGadget <gitgitgadget@gmail.com>
Date
Apr 16, 2026, 09:20 UTC
Message-ID
<650acab79ef5e45b6835b523a37cde184ad60e04.1776331259.git.gitgitgadget@gmail.com>
In-Reply-To
<pull.2087.git.1776331259.gitgitgadget@gmail.com>
From: Matthew John Cheetham <mjcheetham@outlook.com>

Add tests exercising the interaction between http.emptyAuth and servers that advertise Negotiate (SPNEGO) authentication.

Verify that auto mode gives Negotiate a chance via empty auth (resulting in two 401 responses before falling through to credential_fill with Basic credentials), and that false mode strips Negotiate immediately (only one 401 response).

Signed-off-by: Matthew John Cheetham <mjcheetham@outlook.com>
---
 t/t5563-simple-http-auth.sh | 74 +++++++++++++++++++++++++++++++++++++
 1 file changed, 74 insertions(+)
diff --git a/t/t5563-simple-http-auth.sh b/t/t5563-simple-http-auth.sh
index 0063581615..a7d475dd68 100755
--- a/t/t5563-simple-http-auth.sh
+++ b/t/t5563-simple-http-auth.sh
@@ -719,4 +719,78 @@ test_expect_success 'access using three-legged auth' '
 	EOF
 '
 
+test_lazy_prereq SPNEGO 'curl --version | grep -qi "SPNEGO\|GSS-API\|Kerberos\|negotiate"'
+
+test_expect_success SPNEGO 'http.emptyAuth=auto attempts Negotiate before credential_fill' '
+	test_when_finished "per_test_cleanup" &&
+
+	set_credential_reply get <<-EOF &&
+	username=alice
+	password=secret-passwd
+	EOF
+
+	# Basic base64(alice:secret-passwd)
+	cat >"$HTTPD_ROOT_PATH/custom-auth.valid" <<-EOF &&
+	id=1 creds=Basic YWxpY2U6c2VjcmV0LXBhc3N3ZA==
+	EOF
+
+	cat >"$HTTPD_ROOT_PATH/custom-auth.challenge" <<-EOF &&
+	id=1 status=200
+	id=default response=WWW-Authenticate: Negotiate
+	id=default response=WWW-Authenticate: Basic realm="example.com"
+	EOF
+
+	test_config_global credential.helper test-helper &&
+	GIT_TRACE_CURL="$TRASH_DIRECTORY/trace-auto" \
+		git -c http.emptyAuth=auto \
+		ls-remote "$HTTPD_URL/custom_auth/repo.git" &&
+
+	# In auto mode with a Negotiate+Basic server, there should be
+	# three 401 responses: (1) initial no-auth request, (2) empty-auth
+	# retry where Negotiate fails (no Kerberos ticket), (3) libcurl
+	# internal Negotiate retry. The fourth attempt uses Basic
+	# credentials from credential_fill and succeeds.
+	grep "HTTP/[0-9.]* 401" "$TRASH_DIRECTORY/trace-auto" >actual_401s &&
+	test_line_count = 3 actual_401s &&
+
+	expect_credential_query get <<-EOF
+	capability[]=authtype
+	capability[]=state
+	protocol=http
+	host=$HTTPD_DEST
+	wwwauth[]=Negotiate
+	wwwauth[]=Basic realm="example.com"
+	EOF
+'
+
+test_expect_success SPNEGO 'http.emptyAuth=false skips Negotiate' '
+	test_when_finished "per_test_cleanup" &&
+
+	set_credential_reply get <<-EOF &&
+	username=alice
+	password=secret-passwd
+	EOF
+
+	# Basic base64(alice:secret-passwd)
+	cat >"$HTTPD_ROOT_PATH/custom-auth.valid" <<-EOF &&
+	id=1 creds=Basic YWxpY2U6c2VjcmV0LXBhc3N3ZA==
+	EOF
+
+	cat >"$HTTPD_ROOT_PATH/custom-auth.challenge" <<-EOF &&
+	id=1 status=200
+	id=default response=WWW-Authenticate: Negotiate
+	id=default response=WWW-Authenticate: Basic realm="example.com"
+	EOF
+
+	test_config_global credential.helper test-helper &&
+	GIT_TRACE_CURL="$TRASH_DIRECTORY/trace-false" \
+		git -c http.emptyAuth=false \
+		ls-remote "$HTTPD_URL/custom_auth/repo.git" &&
+
+	# With emptyAuth=false, Negotiate is stripped immediately and
+	# credential_fill is called right away. Only one 401 response.
+	grep "HTTP/[0-9.]* 401" "$TRASH_DIRECTORY/trace-false" >actual_401s &&
+	test_line_count = 1 actual_401s
+'
+
 test_done
-- 
gitgitgadget
Previous: Matthew John CheethamNext: Matthew John Cheetham via GitGitGadget
Message 7 of 13 in “http: fix emptyAuth=auto for Negotiate/SPNEGO”
  1. 0/3 http: fix emptyAuth=auto for Negotiate/SPNEGOMatthew John Cheetham via GitGitGadget, Apr 16, 2026
  2. 1/3 http: extract http_reauth_prepare() from retry pathsMatthew John Cheetham via GitGitGadget, Apr 16, 2026
  3. Junio C HamanoApr 16, 2026
  4. 2/3 http: attempt Negotiate auth in http.emptyAuth=auto modeMatthew John Cheetham via GitGitGadget, Apr 16, 2026
  5. Junio C HamanoApr 16, 2026
  6. Matthew John CheethamApr 28, 2026
  7. 3/3 t5563: add tests for http.emptyAuth with NegotiateMatthew John Cheetham via GitGitGadget, Apr 16, 2026
  8. 0/4 http: fix emptyAuth=auto for Negotiate/SPNEGOMatthew John Cheetham via GitGitGadget, Apr 30, 2026
  9. 1/4 http: extract http_reauth_prepare() from retry pathsMatthew John Cheetham via GitGitGadget, Apr 30, 2026
  10. 2/4 http: attempt Negotiate auth in http.emptyAuth=auto modeMatthew John Cheetham via GitGitGadget, Apr 30, 2026
  11. 3/4 t5563: add tests for http.emptyAuth with NegotiateMatthew John Cheetham via GitGitGadget, Apr 30, 2026
  12. 4/4 doc: clarify http.emptyAuth valuesMatthew John Cheetham via GitGitGadget, Apr 30, 2026
  13. Matthew John CheethamApr 30, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.