git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Allow any HTTP authentication scheme, not only basic

From
Martin Storsjö <martin@martin.st>
Date
Apr 1, 2009, 15:06 UTC
Message-ID
<Pine.LNX.4.64.0904011750260.5901@localhost.localdomain>
In-Reply-To
<alpine.DEB.1.00.0903312104010.6676@intel-tinevez-2-302>
Hi,
My patch doesn't seem to come completely without troubles, though.

I still find this a potentially valuable scenario; e.g. for a public repo with push access only over HTTP, but using secure digest authentication instead of sending the credentials in plaintext.

One downside is that it causes a lot more HTTP requests, since libcurl initially tries without any authentication for (almost?) every request, doubling the number of requests made.

Fetching works just fine, but pushing may fail on auth problems in some cases where it wouldn't fail otherwise, if only basic authentication was used and libcurl automatically used that without probing what authentication scheme the server uses.

Things generally seem to work fine with Apache, but with Lighttpd, retrying with proper credentials may fail due to CURLE_SEND_FAIL_REWIND /* 65 - Sending the data requires a rewind that failed */. This issue can be fixed by another patch (that I'll send soon).

Even after fixing that, there still seems to be some issues on some older curl versions; in particular, 7.16.3, shipped in OS X Leopard, returns error code CURLE_HTTP_RETURNED_ERROR instead of retrying properly with authentication.

// Martin
Previous: Johannes Schindelin
Message 4 of 4 in “Allow any HTTP authentication scheme, not only basic”
  1. Allow any HTTP authentication scheme, not only basicMartin Storsjo, Mar 31, 2009
  2. Allow any HTTP authentication scheme, not only basicMartin Storsjo, Mar 31, 2009
  3. Johannes SchindelinMar 31, 2009
  4. Martin StorsjöApr 1, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.