git/list[1] front-page[2] threads[3] people[4] search[5] about
wed 2026-10-07 17:00 UTC

Re: [PATCH] http.c: prompt for username on 403

From
Ashlesh Gawande <git@ashlesh.me>
Date
Dec 9, 2025, 08:22 UTC
Message-ID
<79d2226c-b568-4385-a618-f0d3c06cd0a8@ashlesh.me>
In-Reply-To
<aPAg3gYwzA9fHCC3@fruit.crustytoothpaste.net>
On 10/16/25 04:01, brian m. carlson wrote:
Show 13 quoted lines
> On 2025-10-15 at 14:12:09, Ashlesh Gawande wrote:
>> Oh I see - yeah don't want to erase the credentials.
>> Was trying to figure why 403 was happening instead of a prompt (as I was not
>> aware of netrc file being used).
>> Thanks for the detailed explanation and suggestions Brian!
>>
>> Is it worth it to include the netrc tests in git that I wrote as part of
>> this
> Yes, I think if you have patches to test our netrc handling, those would
> be very welcome.  I was complaining a couple months ago about how we had
> no tests for netrc after I accidentally broke the code that makes it
> work, so I would very much appreciate any tests we could add to make
> that less likely in the future.

I was working on separating the tests and thought about the original proposal a bit more. To stop the credentials from being erased on 403 could something like the following be acceptable?

         else if (results->http_code == 401 || results->http_code == 403) {
                 if ((http_auth.username && http_auth.password) ||\
                     (http_auth.authtype && http_auth.credential)) {
+                       // Do not override existing credentials on 403
+                       if (results->http_code == 403) {
+                               return HTTP_ERROR;
+                       }
+
                         if (http_auth.multistage) {
So then we would prompt on 403 only if credentials are not configured.
Previous: brian m. carlsonNext: brian m. carlson
Message 5 of 11 in “http.c: prompt for username on 403”
  1. http.c: prompt for username on 403Ashlesh Gawande, Oct 14, 2025
  2. brian m. carlsonOct 14, 2025
  3. Ashlesh GawandeOct 15, 2025
  4. brian m. carlsonOct 15, 2025
  5. Ashlesh GawandeDec 9, 2025
  6. brian m. carlsonDec 10, 2025
  7. Ashlesh GawandeDec 10, 2025
  8. Ashlesh GawandeDec 10, 2025
  9. rsbecker@nexbridge.comDec 10, 2025
  10. brian m. carlsonDec 10, 2025
  11. Ashlesh GawandeDec 11, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.