git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git: handling HTTPS proxy w/ password inappropriately

From
YYangfl <mmyangfl@gmail.com>
Date
Feb 5, 2018, 18:16 UTC
Message-ID
<CAAXyoMN_DYHO0BX1fn+97+GPPPFLGya3nCi4SEvDJDRL3-6=dA@mail.gmail.com>
In-Reply-To
<20180205175500.GA104086@aiede.svl.corp.google.com>
2018-02-06 1:55 GMT+08:00 Jonathan Nieder <jrnieder@gmail.com>:
Show 17 quoted lines
> Hi,
>
> Yangfl <mmyangfl@gmail.com> wrote[1]:
>
>> not affected any more
>
> Can you say a little more about this?  Do you mean that newer versions
> of Git are working better for you or that your proxy setup changed?
>
> This looks similar to
> https://public-inbox.org/git/CAHnnmh6QCnHTycbMDLjfFYoXW4dErTZoTHsPrkYdhZKnXcHHYQ@mail.gmail.com/
> to me, which makes me fear it hasn't been fixed.
>
> Thanks,
> Jonathan
>
> [1] http://bugs.debian.org/873424

I just repeated it three times to make sure it works perfectly. However, I still see 2 connection attempts in my wireshark, the first one without password (then FINed), and the following one with.

$ git --version git version 2.15.1

Versions of packages git depends on: ii git-man 1:2.15.1-3 ii libc6 2.26-4 ii libcurl3-gnutls 7.58.0-2 ii liberror-perl 0.17025-1 ii libexpat1 2.2.5-3 ii libpcre2-8-0 10.22-5 ii perl 5.26.1-4 ii zlib1g 1:1.2.8.dfsg-5

Versions of packages git recommends: ii less 487-0.1 ii openssh-client [ssh-client] 1:7.6p1-3 ii patch 2.7.5-1+b2

Versions of packages git suggests: ii gettext-base 0.19.8.1-4 pn git-cvs <none> pn git-daemon-run | git-daemon-sysvinit <none> pn git-doc <none> pn git-el <none> pn git-email <none> pn git-gui <none> pn git-mediawiki <none> pn git-svn <none> pn gitk <none> pn gitweb <none>

Previous: Jonathan Nieder
Message 2 of 2 in “Re: git: handling HTTPS proxy w/ password inappropriately”
  1. Jonathan NiederFeb 5, 2018
  2. YangflFeb 5, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.