From: Ashlesh Gawande Date: Tue, 09 Dec 2025 08:22:49 GMT Subject: Re: [PATCH] http.c: prompt for username on 403 Message-ID: <79d2226c-b568-4385-a618-f0d3c06cd0a8@ashlesh.me> In-Reply-To: On 10/16/25 04:01, brian m. carlson wrote: > On 2025-10-15 at 14:12:09, Ashlesh Gawande wrote: >> Oh I see - yeah don't want to erase the credentials. >> Was trying to figure why 403 was happening instead of a prompt (as I was not >> aware of netrc file being used). >> Thanks for the detailed explanation and suggestions Brian! >> >> Is it worth it to include the netrc tests in git that I wrote as part of >> this > Yes, I think if you have patches to test our netrc handling, those would > be very welcome. I was complaining a couple months ago about how we had > no tests for netrc after I accidentally broke the code that makes it > work, so I would very much appreciate any tests we could add to make > that less likely in the future. I was working on separating the tests and thought about the original proposal a bit more. To stop the credentials from being erased on 403 could something like the following be acceptable?         else if (results->http_code == 401 || results->http_code == 403) {                 if ((http_auth.username && http_auth.password) ||\                     (http_auth.authtype && http_auth.credential)) { +                       // Do not override existing credentials on 403 +                       if (results->http_code == 403) { +                               return HTTP_ERROR; +                       } +                         if (http_auth.multistage) { So then we would prompt on 403 only if credentials are not configured.