git/list[1] front-page[2] threads[3] people[4] search[5] about
wed 2026-10-07 16:55 UTC

Re: [PATCH] http.c: prompt for username on 403

From
Ashlesh Gawande <git@ashlesh.me>
Date
Dec 11, 2025, 06:05 UTC
Message-ID
<888e3dec-e279-47af-8a91-04a06f6eb0af@ashlesh.me>
In-Reply-To
<aTn0BOM07Lyphq_1@fruit.crustytoothpaste.net>
On 12/11/25 03:58, brian m. carlson wrote:
Show 18 quoted lines
> On 2025-12-10 at 12:30:27, Ashlesh Gawande wrote:
>> Oh, that http_code == 403 is my original proposal to prompt for
>> username/password on 403 (I did the diff on top of that instead of base).
>> But you pointed out that it would wipe out existing credentials. This is an
>> attempt to fix that by not prompting on 403 if git credentials are set.
>> So when credentials are provided through default netrc file (such that
>> http_auth.* are not set; git credential helper is not set) then we can still
>> get the prompt on 403.
> As Randall said, I don't think it's a good idea to do this.  It's a
> major change in how functionality works and it will probably break
> users.
>
> I did mention before that a better approach is to add a config to decide
> whether to honour the netrc and I think that would be the right choice
> here.  That lets people opt into different behaviour if they want it
> (and, to be honest, I _do_ very much want to skip netrc for Git
> credentials since I have similar problems as the ones you're describing)
> and avoids breaking things for existing users.

Hmm, okay I understand. Yes probably good idea to skip netrc for Git credentials. Thank you for your input Brian and Randall!

Previous: brian m. carlson
Message 11 of 11 in “http.c: prompt for username on 403”
  1. http.c: prompt for username on 403Ashlesh Gawande, Oct 14, 2025
  2. brian m. carlsonOct 14, 2025
  3. Ashlesh GawandeOct 15, 2025
  4. brian m. carlsonOct 15, 2025
  5. Ashlesh GawandeDec 9, 2025
  6. brian m. carlsonDec 10, 2025
  7. Ashlesh GawandeDec 10, 2025
  8. Ashlesh GawandeDec 10, 2025
  9. rsbecker@nexbridge.comDec 10, 2025
  10. brian m. carlsonDec 10, 2025
  11. Ashlesh GawandeDec 11, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.