git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2] fetch: Strip usernames from url's before storing them

From
Junio C Hamano <gitster@pobox.com>
Date
Apr 15, 2009, 17:19 UTC
Message-ID
<7vbpqxvnpl.fsf@gitster.siamese.dyndns.org>
In-Reply-To
<1239805814-21340-1-git-send-email-ae@op5.se>
Andreas Ericsson <ae@op5.se> writes:
Show 6 quoted lines
> When pulling from a remote, the full URL including username
> is by default added to the commit message. Since it adds
> very little value but could be used by malicious people to
> glean valid usernames (with matching hostnames), we're far
> better off just stripping the username before storing the
> remote URL locally.
Sounds like a sensible thing to do.
Show 8 quoted lines
> +/*
> + * Strip username information from the url and return it in a
> + * newly allocated string which the caller has to free.
> + *
> + * The url's we want to catch are the following:
> + *   ssh://[user@]host.xz[:port]/path/to/repo.git/
> + *   [user@]host.xz:/path/to/repo.git/
> + *   http[s]://[user[:password]@]host.xz/path/to/repo.git
If this is a valid URL:
	scheme://host.xz/path@with@at@sign.git/
we do not want to mistakenly trigger this logic.

I do not know if rsync://me@there/path is supported, but we should generalize to support any scheme://me@there/path to keep the code simpler. You do not do anything special based on the URL scheme other than learning how long the scheme:// part is to copy it anyway. Perhaps like...

char *transport_anonymize_url(const char *url)
{
	char *anon_url, *scheme_prefix, *anon_part;
	size_t len, prefix_len = 0;
	anon_part = strchr(url, '@');
	if (is_local(url) || !anon_part)
		goto literal_copy;
	anon_part++;
	scheme_prefix = strstr(url, "://");
	if (scheme_prefix) {
		const char *cp;
		/* make sure scheme is reasonable */
		for (cp = url; cp < scheme_prefix; cp++) {
			switch (*cp) { /* RFC 1738 2.1 */
			case '+':
			case '.':
			case '-':
				break; /* ok */
			default:
				if (isalnum(*cp))
					break;
				/* it isn't */
				goto literal_copy;
			}
		}
		/* @ past the first slash does not count */
		cp = strchr(scheme_prefix + 3, '/');
		if (cp < anon_part)
			goto literal_copy;
		prefix_len = scheme_prefix - url + 3;
	}
	else if (!strchr(anon_part, ':'))
		/* cannot be "me@there:/path/name" */
		goto literal_copy;
	len = prefix_len + strlen(anon_part);
	anon_url = xmalloc(len + 1);
	memcpy(anon_url, url, prefix_len);
	memcpy(anon_url + prefix_len, anon_part, strlen(anon_part));
	return anon_url;
 literal_copy:
	return xstrdup(url);
}
Previous: Andreas EricssonNext: Andreas Ericsson
Message 9 of 13 in “fetch: Strip usernames from url's before storing them”
  1. fetch: Strip usernames from url's before storing themAndreas Ericsson, Apr 15, 2009
  2. Michael J GruberApr 15, 2009
  3. Andreas EricssonApr 15, 2009
  4. Junio C HamanoApr 15, 2009
  5. Andreas EricssonApr 15, 2009
  6. Johannes SixtApr 15, 2009
  7. Andreas EricssonApr 15, 2009
  8. fetch: Strip usernames from url's before storing themAndreas Ericsson, Apr 15, 2009
  9. Junio C HamanoApr 15, 2009
  10. Andreas EricssonApr 15, 2009
  11. fetch: Strip usernames from url's before storing themAndreas Ericsson, Apr 17, 2009
  12. Andreas EricssonApr 20, 2009
  13. Junio C HamanoApr 20, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.