git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [ANNOUNCE] Git 1.7.8.rc0

From
Junio C Hamano <gitster@pobox.com>
Date
Nov 2, 2011, 19:13 UTC
Message-ID
<7vwrbiibgz.fsf@alter.siamese.dyndns.org>
In-Reply-To
<20111102181041.GA5366@sigill.intra.peff.net>
Jeff King <peff@peff.net> writes:
Show 13 quoted lines
> So the ideal logic is:
>
>   1. look in netrc
>
>   2. If we have a username and no password, ask for password
>
>   3. Otherwise, try it and see if we get a 401.
>
> But we can't do that, because (1) and (3) happen atomically inside of
> curl.
>
> The simplest thing is to just drop the behavior in (2), and let it drop
> to a 401. The extra round trip probably isn't that big a deal.
That is essentially what Stefan's fix is about.
The cases we have "extra" roundtrip are:
 - when you have username@ in URL but no password is stored in .netrc;
 - when you have username@ in URL and no $HOME/.netrc file.

and in such a case using URL without username@ in it as a workaround would save the roundtrip but forces you to type your username@ over and over again, which is _not_ a real workaround.

A workaround for people who want ultimate convenience is to use .netrc to have both username:password, but that is at the cost of potentially reduced security. Having username@ in URL and typing password interactively, if it worked properly, would have been the best of both worlds.

> The other option is to start parsing netrc ourselves, or do the extra
> round trip if we detect ~/.netrc or something. But that last one is
> getting pretty hackish.

I tend to agree that we wouldn't want to parse netrc ourselves (that is what library support e.g. CURLOPT_NETRC is for). The latter is hackish but on the other hand it is a cheap, simple and useful hack.

How would the upcoming keystore support fit in this picture, by the way?
Previous: Jeff KingNext: Jeff King
Message 12 of 26 in “[ANNOUNCE] Git 1.7.8.rc0”
  1. Junio C HamanoOct 31, 2011
  2. Stefan NäweOct 31, 2011
  3. Junio C HamanoOct 31, 2011
  4. Stefan NäweNov 1, 2011
  5. Junio C HamanoNov 1, 2011
  6. Jeff KingNov 1, 2011
  7. Stefan NaeweNov 1, 2011
  8. Stefan NaeweNov 1, 2011
  9. Michael J GruberNov 2, 2011
  10. Jeff KingNov 2, 2011
  11. Jeff KingNov 2, 2011
  12. Junio C HamanoNov 2, 2011
  13. Jeff KingNov 2, 2011
  14. Junio C HamanoNov 3, 2011
  15. Stefan NaeweNov 1, 2011
  16. http-push: don't always prompt for password (Was Re: [ANNOUNCE] Git 1.7.8.rc0)Stefan Näwe, Nov 2, 2011
  17. Michael J GruberNov 2, 2011
  18. Junio C HamanoNov 2, 2011
  19. Jeff KingNov 2, 2011
  20. Junio C HamanoNov 2, 2011
  21. http-push: don't always prompt for passwordStefan Naewe, Nov 4, 2011
  22. Junio C HamanoNov 4, 2011
  23. Jeff KingNov 4, 2011
  24. Junio C HamanoNov 4, 2011
  25. Stefan NaeweNov 4, 2011
  26. Junio C HamanoNov 5, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.