git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[BUG] basic auth not send on empty password in default configuration

From
Xavier Morel <xmo@odoo.com>
Date
Sep 23, 2026, 07:10 UTC
Message-ID
<6fa4c795-7f80-45e7-a42a-ee6e9cfc01cf@odoo.com>
Hit this issue playing with a custom credential helper:
- if the server requires authentication for an operation (returns 401 on
   an un-authenticated request)
- and the credential helper sets an empty username and a non-empty
   password
- the second request git sends is still un-authenticated instead of
   having basic auth set
- git then fails with an "authentication failed" error

If proactiveAuth=basic is enabled, git doesn't mind the empty username and sends the request with basic auth set.

This was directly observed on git 2.47 and 2.55, with curl 8.5.0.

The issue seems to come from init_curl_http_auth: if the username is unset *or empty*, it exits immediately unless proactive auth is enabled, which matches the symptoms. From this it looks like an other workaround would be for the credential helper to precompute the `credential` value and return that instead of username/password, as that is guaranteed to be non-empty.

Either way the current behaviour is somewhat surprising as (AFAIK) nothing in basic auth requires non-empty usernames (or even passwords), and importantly git doesn't report anything odd except the connection failing, the lack of auth on the second attempt is only visible when enabling GIT_CURL_VERBOSE and comparing a successful auth with an unsuccessful one (or on the server side, but there if the server is bespoke one can easily chase ghosts assuming the error is obviously somewhere in the bespoke code because select isn't broken).

Message 1 of 1 in “[BUG] basic auth not send on empty password in default configuration”
  1. Xavier MorelSep 23, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.