git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2] Add an option for using any HTTP authentication scheme, not only basic

From
Martin Storsjö <martin@martin.st>
Date
Apr 14, 2009, 21:56 UTC
Message-ID
<Pine.LNX.4.64.0904150054470.7479@localhost.localdomain>

This adds the configuration option http.authAny (overridable with the environment variable GIT_HTTP_AUTH_ANY), for instructing curl to allow any HTTP authentication scheme, not only basic (which sends the password in plaintext).

When this is enabled, curl has to do double requests most of the time, in order to discover which HTTP authentication method to use, which lowers the performance slightly. Therefore this isn't enabled by default.

One example of another authentication scheme to use is digest, which doesn't send the password in plaintext, but uses a challenge-response mechanism instead. Using digest authentication in practice requires at least curl 7.18.1, due to bugs in the digest handling in earlier versions of curl.

Signed-off-by: Martin Storsjo <martin@martin.st>
---
Repost with the curl version checked in only one place.
 Documentation/config.txt |    7 +++++++
 http.c                   |   22 ++++++++++++++++++++++
 2 files changed, 29 insertions(+), 0 deletions(-)
diff --git a/Documentation/config.txt b/Documentation/config.txt
index f3ebd2f..1515d77 100644
--- a/Documentation/config.txt
+++ b/Documentation/config.txt
@@ -1011,6 +1011,13 @@ http.noEPSV::
 	support EPSV mode. Can be overridden by the 'GIT_CURL_FTP_NO_EPSV'
 	environment variable. Default is false (curl will use EPSV).
 
+http.authAny::
+	Allow any HTTP authentication method, not only basic. Enabling
+	this lowers the performance slightly, by having to do requests
+	without any authentication to discover the authentication method
+	to use. Can be overridden by the 'GIT_HTTP_AUTH_ANY'
+	environment variable. Default is false.
+
 i18n.commitEncoding::
 	Character encoding the commit messages are stored in; git itself
 	does not care per se, but this information is necessary e.g. when
diff --git a/http.c b/http.c
index 2e3d649..49b8441 100644
--- a/http.c
+++ b/http.c
@@ -3,6 +3,10 @@
 int data_received;
 int active_requests;
 
+#if LIBCURL_VERSION_NUM >= 0x070a06
+#define LIBCURL_CAN_HANDLE_AUTH_ANY
+#endif
+
 #ifdef USE_CURL_MULTI
 static int max_requests = -1;
 static CURLM *curlm;
@@ -26,6 +30,9 @@ static long curl_low_speed_time = -1;
 static int curl_ftp_no_epsv;
 static const char *curl_http_proxy;
 static char *user_name, *user_pass;
+#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY
+static int curl_http_auth_any = 0;
+#endif
 
 static struct curl_slist *pragma_header;
 
@@ -150,6 +157,12 @@ static int http_options(const char *var, const char *value, void *cb)
 	}
 	if (!strcmp("http.proxy", var))
 		return git_config_string(&curl_http_proxy, var, value);
+#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY
+	if (!strcmp("http.authany", var)) {
+		curl_http_auth_any = git_config_bool(var, value);
+		return 0;
+	}
+#endif
 
 	/* Fall back on the default ones */
 	return git_default_config(var, value, cb);
@@ -184,6 +197,10 @@ static CURL *get_curl_handle(void)
 #if LIBCURL_VERSION_NUM >= 0x070907
 	curl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);
 #endif
+#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY
+	if (curl_http_auth_any)
+		curl_easy_setopt(result, CURLOPT_HTTPAUTH, CURLAUTH_ANY);
+#endif
 
 	init_curl_http_auth(result);
 
@@ -329,6 +346,11 @@ void http_init(struct remote *remote)
 	if (getenv("GIT_CURL_FTP_NO_EPSV"))
 		curl_ftp_no_epsv = 1;
 
+#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY
+	if (getenv("GIT_HTTP_AUTH_ANY"))
+		curl_http_auth_any = 1;
+#endif
+
 	if (remote && remote->url && remote->url[0])
 		http_auth_init(remote->url[0]);
 
-- 
1.6.0.2
Next: Tay Ray Chuan
Message 1 of 22 in “Add an option for using any HTTP authentication scheme, not only basic”
  1. Add an option for using any HTTP authentication scheme, not only basicMartin Storsjö, Apr 14, 2009
  2. 0/2 http: allow multi-pass authenticationTay Ray Chuan, Nov 27, 2009
  3. 1/2 http: maintain curl sessionsTay Ray Chuan, Nov 27, 2009
  4. 2/2 Add an option for using any HTTP authentication scheme, not only basicTay Ray Chuan, Nov 27, 2009
  5. Martin StorsjöDec 1, 2009
  6. Allow curl to rewind the RPC read bufferMartin Storsjö, Dec 1, 2009
  7. Shawn O. PearceDec 1, 2009
  8. Tay Ray ChuanDec 1, 2009
  9. Shawn O. PearceDec 1, 2009
  10. Martin StorsjöDec 1, 2009
  11. Junio C HamanoDec 1, 2009
  12. Tay Ray ChuanDec 2, 2009
  13. Martin StorsjöDec 2, 2009
  14. Allow curl to rewind the RPC read buffer at any timeMartin Storsjö, Dec 1, 2009
  15. Shawn O. PearceDec 1, 2009
  16. Martin StorsjöDec 1, 2009
  17. Tay Ray ChuanDec 2, 2009
  18. Daniel StenbergDec 1, 2009
  19. Tay Ray ChuanDec 2, 2009
  20. Daniel StenbergDec 2, 2009
  21. Martin StorsjöDec 2, 2009
  22. Daniel StenbergDec 2, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.