git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: OAuth2 support in git?

From
Christian Halstrick <christian.halstrick@gmail.com>
Date
Jun 19, 2018, 12:36 UTC
Message-ID
<CAENte7hzJw5VW2JFLV1Pj5v4u52=xL-dvhcfRACYa2eUvQnAVA@mail.gmail.com>
In-Reply-To
<20180618212614.GA2504@sigill.intra.peff.net>

What is not clear to me is how we can make use of the servers initial response in order control which credential helper to call and how to transport the credentials.

Imagine we try to clone over http. The initial request sent to the server may not contain a "Authorization: ..." header and the server responds with Unauthorized. But the server response contains hints like a "WWW-Authenticate: Basic realm=..." line or a "WWW-Authenticate: Bearer realm=..." line which helps choosing the authentication scheme used next. Maybe the server even responds with both lines telling I would accept BASIC or BEARER.

I can imagine that we want libcurl to deal with that decisions. But even then. How do we make sure the our credential helpers can act return either user/password or bearer tokens based on the server response? If credential helper would have access to the servers response (or only relevant parts of it?) it could decide whether to feel responsible for that server or not and what data to return.

And if credential helper could optionally give metadata about the kind credential they offer (e.g. "I return user/password" or "I return a bearer token") then core code could know where to transport this data. E.g. in a "Authorization: Basic ..." or a "Authorization: Bearer ..." field.

Ciao
  Chris
Previous: Jeff KingNext: Jeff King
Message 11 of 12 in “OAuth2 support in git?”
  1. Christian HalstrickJun 14, 2018
  2. brian m. carlsonJun 14, 2018
  3. Jeff KingJun 14, 2018
  4. Randall S. BeckerJun 14, 2018
  5. Jeff KingJun 14, 2018
  6. brian m. carlsonJun 14, 2018
  7. Johannes SchindelinJun 17, 2018
  8. Jeff KingJun 18, 2018
  9. Junio C HamanoJun 18, 2018
  10. Jeff KingJun 18, 2018
  11. Christian HalstrickJun 19, 2018
  12. Jeff KingJun 19, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.