Re: [PATCH v4] credential: new attribute password_expiry_utc
- From
Calvin Wan <calvinwan@google.com>
- Date
- Feb 22, 2023, 19:22 UTC
- Message-ID
- <CAFySSZA-f+Qgs2bT_Vkj79PvXqGarBLtqeyEN3vWCj44no6Eig@mail.gmail.com>
- In-Reply-To
- <pull.1443.v4.git.git.1676701977347.gitgitgadget@gmail.com>
Show 14 quoted lines
> static int run_credential_helper(struct credential *c,
> @@ -342,6 +353,12 @@ void credential_fill(struct credential *c)
>
> for (i = 0; i < c->helpers.nr; i++) {
> credential_do(c, c->helpers.items[i].string, "get");
> + if (c->password_expiry_utc < time(NULL)) {
> + /* Discard expired password */
> + FREE_AND_NULL(c->password);
> + /* Reset expiry to maintain consistency */
> + c->password_expiry_utc = TIME_MAX;
> + }
> if (c->username && c->password)
> return;
> if (c->quit)Thanks for clarifying this block!
Overall, this patch is additive and shouldn't cause any regressions for current users of credential/credential-helper so I'm all for adding an expiry attribute to alleviate the use case pains you described above.
Reviewed-by: Calvin Wan <calvinwan@google.com>