git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] credential: clear expired c->credential in addition to c->password

From
Junio C Hamano <gitster@pobox.com>
Date
Jun 4, 2024, 18:24 UTC
Message-ID
<xmqqed9cva5s.fsf@gitster.g>
In-Reply-To
<20240604180224.1484537-1-aplattner@nvidia.com>
Aaron Plattner <aplattner@nvidia.com> writes:
> When a struct credential expires, credential_fill() clears c->password
> so that clients don't try to use it later. However, a struct cred that
> uses an alternate authtype won't have a password, but might have a
> credential stored in c->credential. Clear that too.

Hmph, piling another thing on top of these selected "discard/reset" we already have should make us rethink a few things.

 - Is this the only place we discard/reset/clear?
 - Isn't there already a helper function that was DESIGNED to do
   this for us?
 - Are all these places we discard/reset/clear using that helper
   function?

For example, when we rejecting credential, shouldn't we be clearing the same members of the structure as we notice that the auth material is stale and has expired?

There is credential_clear() and credential_clear_secrets(). Would one of these want to be reused in this (and also reject) context?

Previous: Aaron PlattnerNext: Aaron Plattner
Message 2 of 3 in “credential: clear expired c->credential in addition to c->password”
  1. credential: clear expired c->credential in addition to c->passwordAaron Plattner, Jun 4, 2024
  2. Junio C HamanoJun 4, 2024
  3. Aaron PlattnerJun 4, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.