git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git client enhancement request

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
May 13, 2024, 21:19 UTC
Message-ID
<ZkKD95VBlmsUJdB5@tapette.crustytoothpaste.net>
In-Reply-To
<051d01daa567$caa22750$5fe675f0$@gmail.com>
On 2024-05-13 at 19:00:14, lbdyck@gmail.com wrote:
> I have to interject here that the git client doing a push must be fully
> authenticated which implies to me that all the information required is
> available to do so and allow the server repository to be updated.

First of all, the authentication required to _create_ a repository need not be the same as to _read_ or _write_ a repository. It might require a totally different set of scopes or privileges to create a new repository, which many users will have avoided giving to their credentials for least-privilege reasons.

Second, there's no standard API to perform that functionality, and the implementation varies widely on different forges. There are also people who don't use forges at all, or use tooling like gitolite[0] that handles this differently. Adding such functionality into the Git protocol requires intertwining that functionality and the services that provide it with the standard forge API, so it's likely to be very complex for forges to implement using the same functionality as Git uses currently.

Third, we specifically try not to prioritize any individual piece of software or project here. Even if there are many common forges, we won't ship tooling that's specific to GitHub, GitLab, or Bitbucket, since that prioritizes those users over others. Since there's no standard API for this, we won't be adding any forge-specific functionality to Git.

Even if we decided to implement a standard API for doing this, it doesn't mean that forges would adopt it. Many forges don't implement `git-archive` over SSH, for example, since it's hard to cache versus using HTTP.

[0] gitolite actually allows you to create repositories by just pushing to them if you have permissions to do so in the configuration.

-- 
brian m. carlson (they/them or he/him)
Toronto, Ontario, CA
Previous: lbdyck@gmail.comNext: rsbecker@nexbridge.com
Message 6 of 8 in “git client enhancement request”
  1. lbdyck@gmail.comMay 13, 2024
  2. Sean AllredMay 13, 2024
  3. lbdyck@gmail.comMay 13, 2024
  4. Junio C HamanoMay 13, 2024
  5. lbdyck@gmail.comMay 13, 2024
  6. brian m. carlsonMay 13, 2024
  7. rsbecker@nexbridge.comMay 13, 2024
  8. lbdyck@gmail.comMay 13, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.