git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Preserve the protection mode for the Git config files

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Jul 22, 2009, 22:37 UTC
Message-ID
<alpine.DEB.1.00.0907230031450.3155@pacific.mpi-cbg.de>
In-Reply-To
<20090723070815.6117@nanako3.lavabit.com>
Hi,
On Thu, 23 Jul 2009, Nanako Shiraishi wrote:
> 1. Why would you keep sensitive information in the config file in the 
>    first place? Wouldn't it be better to introduce a level of 
>    indirection, making a variable in the config file to point to a 
>    private file only you can read and store secrets in the latter?

I agree that secret information should probably go to another file, although care has to be taken not to write that other file with "git config -f", as that would display the very same issue.

> 2. Why is your config file more secret than your history?

That one's easy. If you store passwords in the config file, it _is_ more secret than the history. You might be very willing to show people what you did, but still be unwilling to allow people to push commits with your credentials.

> Wouldn't it solve your problem without any patch if you set 
> core.sharedrepository to 0600?

I doubt it, as that config setting does not change anything in the working directory retro-actively.

You _could_ chmod 0700 .git. But that is probably not what Catalin wanted.

Ciao, Dscho

Previous: Nanako ShiraishiNext: Catalin Marinas
Message 4 of 5 in “Preserve the protection mode for the Git config files”
  1. Preserve the protection mode for the Git config filesCatalin Marinas, Jul 21, 2009
  2. Junio C HamanoJul 22, 2009
  3. Nanako ShiraishiJul 22, 2009
  4. Johannes SchindelinJul 22, 2009
  5. Catalin MarinasJul 27, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.