git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] urlmatch: do not allow passwords in URLs by default

From
Junio C Hamano <gitster@pobox.com>
Date
May 3, 2021, 03:38 UTC
Message-ID
<xmqqk0oga3ma.fsf@gitster.g>
In-Reply-To
<CAP8UFD1Wm2e7Q3XY346-fFWMhdGHV_1Kp=wo8cqsx71j7Sg-dQ@mail.gmail.com>
Christian Couder <christian.couder@gmail.com> writes:
> Another helpful thing to do might be to add --user and maybe
> --password options to some commands like 'clone', 'fetch', 'remote
> add', etc.
Why?

We cannot get rid of <scheme>://<user>:<pass>@<host>/<path> right away, but I'd imagine that we'd prefer to see fewer places on the command line for users to leave the password that would end up in their .bashrc and other places.

And I like the idea raised elsewhere in the thread to forward the <pass> to credential helper and leave ":<pass>" part out of the stored URL.

Thanks.
Previous: Christian CouderNext: Ævar Arnfjörð Bjarmason
Message 7 of 10 in “urlmatch: do not allow passwords in URLs by default”
  1. urlmatch: do not allow passwords in URLs by defaultDerrick Stolee via GitGitGadget, Apr 30, 2021
  2. Jeff KingApr 30, 2021
  3. Derrick StoleeMay 3, 2021
  4. Jeff KingMay 3, 2021
  5. brian m. carlsonMay 1, 2021
  6. Christian CouderMay 1, 2021
  7. Junio C HamanoMay 3, 2021
  8. Ævar Arnfjörð BjarmasonMay 1, 2021
  9. Ævar Arnfjörð BjarmasonMay 1, 2021
  10. Robert CoupMay 3, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.