git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 4/4] doc: clarify http.emptyAuth values

From
Matthew John Cheetham via GitGitGadget <gitgitgadget@gmail.com>
Date
Apr 30, 2026, 10:54 UTC
Message-ID
<e0f236767f81ea60f90749d1bc00ab78081efd0e.1777546472.git.gitgitgadget@gmail.com>
In-Reply-To
<pull.2087.v2.git.1777546472.gitgitgadget@gmail.com>
From: Matthew John Cheetham <mjcheetham@outlook.com>

The existing description of http.emptyAuth explains the purpose of the setting but never says what values it accepts. Readers have to infer from context (or read the source) that it takes 'true', 'false', or 'auto', and what each one means.

Document the three accepted values explicitly:
* 'auto' (the default) only sends empty credentials when the server's
  401 response advertises a mechanism that requires them, such as
  GSS-Negotiate. This matches the long-standing auto-detection
  behaviour added in 40a18fc77c (http: add an "auto" mode for
  http.emptyauth, 2017-02-25).
* 'true' unconditionally sends empty credentials on the very first
  request, before any 401 response, for callers that know they want
  this behaviour up front.
* 'false' disables the feature entirely; mechanisms that depend on
  empty credentials, such as GSS-Negotiate, will not work in this
  mode.
Signed-off-by: Matthew John Cheetham <mjcheetham@outlook.com>
---
 Documentation/config/http.adoc | 13 ++++++++++++-
 1 file changed, 12 insertions(+), 1 deletion(-)
diff --git a/Documentation/config/http.adoc b/Documentation/config/http.adoc
index 849c89f36c..792a71b413 100644
--- a/Documentation/config/http.adoc
+++ b/Documentation/config/http.adoc
@@ -59,7 +59,18 @@ http.emptyAuth::
 	Attempt authentication without seeking a username or password.  This
 	can be used to attempt GSS-Negotiate authentication without specifying
 	a username in the URL, as libcurl normally requires a username for
-	authentication.
+	authentication. Possible values are:
++
+--
+* `auto` (default) - Send empty credentials only if the server's 401 response
+  advertises an authentication mechanism that requires them (such as
+  GSS-Negotiate); otherwise fall back to prompting via the credential helper.
+* `true` - Always send empty credentials on the very first request, before
+  receiving any 401 response from the server.
+* `false` - Never send empty credentials. Mechanisms that require
+  empty credentials or an explicit username, such as GSS-Negotiate, will not
+  work.
+--
 
 http.proactiveAuth::
 	Attempt authentication without first making an unauthenticated attempt and
-- 
gitgitgadget
Previous: Matthew John Cheetham via GitGitGadgetNext: Matthew John Cheetham
Message 12 of 13 in “http: fix emptyAuth=auto for Negotiate/SPNEGO”
  1. 0/3 http: fix emptyAuth=auto for Negotiate/SPNEGOMatthew John Cheetham via GitGitGadget, Apr 16, 2026
  2. 1/3 http: extract http_reauth_prepare() from retry pathsMatthew John Cheetham via GitGitGadget, Apr 16, 2026
  3. Junio C HamanoApr 16, 2026
  4. 2/3 http: attempt Negotiate auth in http.emptyAuth=auto modeMatthew John Cheetham via GitGitGadget, Apr 16, 2026
  5. Junio C HamanoApr 16, 2026
  6. Matthew John CheethamApr 28, 2026
  7. 3/3 t5563: add tests for http.emptyAuth with NegotiateMatthew John Cheetham via GitGitGadget, Apr 16, 2026
  8. 0/4 http: fix emptyAuth=auto for Negotiate/SPNEGOMatthew John Cheetham via GitGitGadget, Apr 30, 2026
  9. 1/4 http: extract http_reauth_prepare() from retry pathsMatthew John Cheetham via GitGitGadget, Apr 30, 2026
  10. 2/4 http: attempt Negotiate auth in http.emptyAuth=auto modeMatthew John Cheetham via GitGitGadget, Apr 30, 2026
  11. 3/4 t5563: add tests for http.emptyAuth with NegotiateMatthew John Cheetham via GitGitGadget, Apr 30, 2026
  12. 4/4 doc: clarify http.emptyAuth valuesMatthew John Cheetham via GitGitGadget, Apr 30, 2026
  13. Matthew John CheethamApr 30, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.