git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] http authentication via prompts

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Mar 5, 2009, 10:55 UTC
Message-ID
<alpine.DEB.1.00.0903051149280.6524@intel-tinevez-2-302>
In-Reply-To
<49AF25BF.5060706@gmail.com>
Hi,
Disclaimer: if you are offended by constructive criticism, or likely to 
answer with insults to the comments I offer, please stop reading this mail 
now (and please do not answer my mail, either). :-)
Still with me?  Good.  Nice to meet you.

Just for the record: responding to a patch is my strongest way of saying that I appreciate your work.

On Wed, 4 Mar 2009, Mike Gaffney wrote:
Show 7 quoted lines
> Currently git over http only works with a .netrc file which required 
> that you store your password on the file system in plaintext. This 
> commit adds to configuration options for http for a username and an 
> optional password. If a http.username is set, then the .netrc file is 
> ignored and the username is used instead. If a http.password is set, 
> then that is used as well, otherwise the user is prompted for their 
> password.
>From the subject, I would have expected a way to type in the password 

instead of storing it. (Think getpass()... which would pose problems with Windows support, of course.)

FWIW by having it in .git/config (which is most likely more world-readable than $HOME/.netrc ever will be) does not provide any security over .netrc.

And I doubt that http.username is a good choice: what if you have multiple http:// URLs with different usernames/passwords? So would it not make more sense to make this remote.<name>.user and ...password?

Ciao, Dscho

Previous: Junio C HamanoNext: Mike Gaffney
Message 3 of 6 in “http authentication via prompts”
  1. http authentication via promptsMike Gaffney, Mar 5, 2009
  2. Junio C HamanoMar 5, 2009
  3. Johannes SchindelinMar 5, 2009
  4. Mike GaffneyMar 5, 2009
  5. Jeff KingMar 5, 2009
  6. Fredrik SkolmliMar 6, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.