git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH 3/3] Allow empty user name in HTTP authentication

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
May 13, 2022, 23:51 UTC
Message-ID
<Yn7vCg6Rl7TYRw82@camp.crustytoothpaste.net>
In-Reply-To
<20220513070416.37235-4-Simon.Richter@hogyros.de>
On 2022-05-13 at 07:04:16, Simon.Richter@hogyros.de wrote:
Show 5 quoted lines
> From: Simon Richter <Simon.Richter@hogyros.de>
> 
> When using a Personal Access Token in Microsoft DevOps server, the username
> can be empty, so users might expect that pressing return on an username
> prompt will work.

I don't think this is a good idea. libcurl relies on CURLOPT_USERPWD being set to enable authentication, and before the appearance of http.emptyAuth, it was extremely common for Kerberos users to specify an empty username to get Git to authenticate properly. I probably still have some repositories on my system configured that way.

I believe GitHub can also accept an empty username with a PAT, but it can also accept a dummy (e.g., "token"), which I would hope Azure DevOps can do as well. In such a case, the documentation for Azure DevOps should just be updated to tell people to specify something like "token" or their username.

-- 
brian m. carlson (he/him or they/them)
Toronto, Ontario, CA
Previous: simon.richter@hogyros.deNext: simon.richter@hogyros.de
Message 3 of 7 in “Allow configuration of HTTP authentication method”
  1. 0/3 Allow configuration of HTTP authentication methodsimon.richter@hogyros.de, May 13, 2022
  2. 3/3 Allow empty user name in HTTP authenticationsimon.richter@hogyros.de, May 13, 2022
  3. brian m. carlsonMay 13, 2022
  4. 1/3 Rename proxy_authmethods -> authmethodssimon.richter@hogyros.de, May 13, 2022
  5. Junio C HamanoMay 13, 2022
  6. 2/3 Add config option/env var to limit HTTP auth methodssimon.richter@hogyros.de, May 13, 2022
  7. Junio C HamanoMay 13, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.