git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Support username and password inside URL

From
Junio C Hamano <junkio@cox.net>
Date
Nov 24, 2005, 22:14 UTC
Message-ID
<7vbr09n16w.fsf@assigned-by-dhcp.cox.net>
In-Reply-To
<87d5kraxsr.fsf@litku.valo.iki.fi>
Kalle Valo <Kalle.Valo@iki.fi> writes:
Show 5 quoted lines
> Actually I'm going to be only user of the private git repository and
> it's going to be permanent. I have multiple computers in different
> locations (servers, workstations, laptops) and I would like to
> distribute my private files (configuration files, scripts etc.) to all
> of them using git.

Fair enough. Is "git-push ssh://these.machines/" (or from these.machines "git-fetch ssh://mother.ship/") more trouble than having HTTP server on your mother ship machine?

> ... The problem with randomized URL (like you
> suggested) is that if some person or a search engine finds the URL
> somehow, then there's nothing stopping the information leak.

Hmph. I had an impression that the obscure URL scheme like in my example http://members.cox.net/junkio/r0ZIEF/5S54m/ is as robot safe as auth embedding URL. That is, if somebody feeds auth-embedding URL to robots I suspect they can follow it just fine. Of course obscure URL needs to be protected by forbidding dirindex at higher level directories and not posting it to public forum [*1*], for the same reason you have to keep the auth embedding URL from public.

[Footnote]

*1* I suspect some robots have already tried to harvest what is found at that URL since I posted the message to the list.

Previous: Kalle ValoNext: Johannes Schindelin
Message 6 of 8 in “HTTP basic authentication support”
  1. Kalle ValoNov 20, 2005
  2. Support username and password inside URLKalle Valo, Nov 20, 2005
  3. Junio C HamanoNov 20, 2005
  4. Krzysztof HalasaNov 20, 2005
  5. Kalle ValoNov 23, 2005
  6. Junio C HamanoNov 24, 2005
  7. Johannes SchindelinNov 24, 2005
  8. Junio C HamanoNov 24, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.