From: Junio C Hamano Date: Mon, 03 May 2021 03:38:21 GMT Subject: Re: [PATCH] urlmatch: do not allow passwords in URLs by default Message-ID: In-Reply-To: Christian Couder writes: > Another helpful thing to do might be to add --user and maybe > --password options to some commands like 'clone', 'fetch', 'remote > add', etc. Why? We cannot get rid of ://:@/ right away, but I'd imagine that we'd prefer to see fewer places on the command line for users to leave the password that would end up in their .bashrc and other places. And I like the idea raised elsewhere in the thread to forward the to credential helper and leave ":" part out of the stored URL. Thanks.