git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Add persistent-https to contrib

From
Junio C Hamano <gitster@pobox.com>
Date
May 24, 2012, 20:51 UTC
Message-ID
<7vlikhwbdc.fsf@alter.siamese.dyndns.org>
In-Reply-To
<CAJo=hJt=q-ZnLrqzcfGrKNcao2MPDSRt3Y_r2OOfu75++N+3zw@mail.gmail.com>
Shawn Pearce <spearce@spearce.org> writes:
Show 8 quoted lines
> The persistent-https code tells the git credential helper the
> connection is "secure" (that is the proxy will use SSL as it exits the
> local machine) by setting GIT_GOOGLE_CREDENTIAL_CORPSSO_ENABLE=1 in
> the environment. This leaked from our internal version of the proxy,
> Colby was supposed to scrub this string before open sourcing. :-)
>
> So now everyone knows $DAYJOB = Google, we have a credential helper,
> and it supports some sort of corporate single sign on. Whee.

It is obviously needed to drop that bit from the public version (and have you guys keep an internal fork to add it back), but I have to wonder if this is an indication that something like that is useful in general.

More specifically, this environment variable is a way to tell the wrapped helper who is wrapping it. Users outside Google's environment of the persistent-https helper obviously would not care about the corporate sanitary sewer overflow mechanism, but they may have a similar need to tweak what happens inside the git-remote-http that is driven by the persistent helper. They would not care about "we can enable corpsso", but they would benefit from knowing that either:

 (1) the connection is "secure" (by the definition above); or
 (2) the connection is going to this particular helper.

Conceptually, an approach to allow chain of helpers tell which one(s) of defined set of attributes (e.g. "secure") are in effect, e.g. (1), might be cleaner, but it probably is a bit too early overengineering (I do not think we know if there is a good set of common attributes various helpers might want to implement upstream and pay attention downstream) at this point. But at least it might not hurt to give the downstream to find out what upstream is driving them.

Hrm?
Previous: Daniel StenbergNext: Colby Ranger
Message 9 of 12 in “Add persistent-https to contrib”
  1. Add persistent-https to contribColby Ranger, May 23, 2012
  2. Junio C HamanoMay 24, 2012
  3. Shawn PearceMay 24, 2012
  4. Jeff KingMay 24, 2012
  5. Shawn PearceMay 24, 2012
  6. Shawn PearceMay 24, 2012
  7. Jeff KingMay 24, 2012
  8. Daniel StenbergMay 24, 2012
  9. Junio C HamanoMay 24, 2012
  10. Colby RangerMay 29, 2012
  11. Add persistent-https to contribColby Ranger, May 29, 2012
  12. Junio C HamanoMay 29, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.