git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] http(s): automatically try NTLM authentication first

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Feb 23, 2017, 17:08 UTC
Message-ID
<alpine.DEB.2.20.1702231806340.3767@virtualbox>
In-Reply-To
<20170222213410.iak43asq775tzr42@sigill.intra.peff.net>
Hi Peff,
On Wed, 22 Feb 2017, Jeff King wrote:
Show 50 quoted lines
> On Wed, Feb 22, 2017 at 01:16:33PM -0800, Junio C Hamano wrote:
> 
> > David Turner <David.Turner@twosigma.com> writes:
> > 
> > > Always, no.  For failed authentication (or authorization),
> > > apparently, yes.  I tested this by  setting the variable to false
> > > and then true, and trying to Push to a github repository which I
> > > didn't have write access to, with both an empty username
> > > (https://@:github.com/...) and no username (http://github.com/...).
> > > I ran this under GIT_CURL_VERBOSE=1 and I saw two 401 responses in
> > > the "http.emptyauth=true" case and one in the false case.  I also
> > > tried with a repo that I did have access to (first configuring the
> > > necessary tokens for HTTPS push access), and saw two 401 responses
> > > in *both* cases.  
> > 
> > Thanks; that matches my observation.  I do not think we care about
> > an extra roundtrip for the failure case, but as long as we do not
> > increase the number of roundtrip in the normal case, we can declare
> > that this is an improvement.  I am not quite sure where that extra
> > 401 comes from in the normal case, and that might be an indication
> > that we already are doing something wrong, though.
> 
> This patch drops the useless probe request:
> 
> diff --git a/http.c b/http.c
> index 943e630ea..7b4c2db86 100644
> --- a/http.c
> +++ b/http.c
> @@ -1663,6 +1663,9 @@ static int http_request(const char *url,
>  		curlinfo_strbuf(slot->curl, CURLINFO_EFFECTIVE_URL,
>  				options->effective_url);
>  
> +	if (results.auth_avail == CURLAUTH_BASIC)
> +		http_auth_methods = CURLAUTH_BASIC;
> +
>  	curl_slist_free_all(headers);
>  	strbuf_release(&buf);
>  
> 
> but setting http.emptyauth adds back in the useless request. I think
> that could be fixed by skipping the empty-auth thing when
> http_auth_methods does not have CURLAUTH_NEGOTIATE in it (or perhaps
> other methods need it to, so maybe skip it if _just_ BASIC is set).
> 
> I suspect the patch above could probably be generalized as:
> 
>   /* cut out methods we know the server doesn't support */
>   http_auth_methods &= results.auth_avail;
> 
> and let curl figure it out from there.

Maybe this patch (or a variation thereof) would also be able to fix this problem with the patch:

	https://github.com/git-for-windows/git/issues/1034

Short version: for certain servers (that do *not* advertise Negotiate), setting emptyauth to true will result in a failed fetch, without letting the user type in their credentials.

Ciao, Johannes

Previous: Jeff KingNext: Junio C Hamano
Message 6 of 38 in “http(s): automatically try NTLM authentication first”
  1. http(s): automatically try NTLM authentication firstDavid Turner, Feb 22, 2017
  2. Junio C HamanoFeb 22, 2017
  3. David TurnerFeb 22, 2017
  4. Junio C HamanoFeb 22, 2017
  5. Jeff KingFeb 22, 2017
  6. Johannes SchindelinFeb 23, 2017
  7. Junio C HamanoFeb 23, 2017
  8. Jeff KingFeb 23, 2017
  9. Junio C HamanoFeb 23, 2017
  10. Jeff KingFeb 23, 2017
  11. Johannes SchindelinFeb 25, 2017
  12. brian m. carlsonFeb 22, 2017
  13. Jeff KingFeb 22, 2017
  14. Junio C HamanoFeb 23, 2017
  15. Junio C HamanoFeb 23, 2017
  16. Jeff KingFeb 23, 2017
  17. David TurnerFeb 23, 2017
  18. brian m. carlsonFeb 23, 2017
  19. Mantas MikulėnasFeb 23, 2017
  20. Jeff KingFeb 22, 2017
  21. Junio C HamanoFeb 22, 2017
  22. Jeff KingFeb 22, 2017
  23. Junio C HamanoFeb 22, 2017
  24. Jeff KingFeb 22, 2017
  25. Junio C HamanoFeb 22, 2017
  26. Jeff KingFeb 22, 2017
  27. 2/2 http: add an "auto" mode for http.emptyauthJeff King, Feb 22, 2017
  28. David TurnerFeb 23, 2017
  29. Jeff KingFeb 23, 2017
  30. David TurnerFeb 23, 2017
  31. Jeff KingFeb 23, 2017
  32. David TurnerFeb 23, 2017
  33. Johannes SchindelinFeb 25, 2017
  34. Jeff KingFeb 25, 2017
  35. http: add an "auto" mode for http.emptyauthJeff King, Feb 25, 2017
  36. Junio C HamanoFeb 27, 2017
  37. Johannes SchindelinFeb 28, 2017
  38. 1/2 http: restrict auth methods to what the server advertisesJeff King, Feb 22, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.