git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v3] t5550: add netrc tests for http 401/403

From
Junio C Hamano <gitster@pobox.com>
Date
Feb 6, 2026, 05:05 UTC
Message-ID
<xmqqms1mihqo.fsf@gitster.g>
In-Reply-To
<20260107074724.13165-1-git@ashlesh.me>
Ashlesh Gawande <git@ashlesh.me> writes:
Show 20 quoted lines
> git allows using .netrc file to supply credentials for HTTP auth.
> Three test cases are added in this patch to provide missing coverage
> when cloning over HTTP using .netrc file:
>
>   - First test case checks that the git clone is successful when credentials
>     are provided via .netrc file
>   - Second test case checks that the git clone fails when the .netrc file
>     provides invalid credentials. The HTTP server is expected to return
>     401 Unauthorized in such a case. The test checks that the user is
>     provided with a prompt for username/password on 401 to provide
>     the valid ones.
>   - Third test case checks that the git clone fails when the .netrc file
>     provides credentials that are valid but do not have permission for
>     this user. For example one may have multiple tokens in GitHub
>     and uses the one which was not authorized for cloning this repo.
>     In such a case the HTTP server returns 403 Forbidden.
>     For this test, the apache.conf is modified to return a 403
>     on finding a forbidden-user. No prompt for username/password is
>     expected after the 403 (unlike 401). This is because prompting may wipe
>     out existing credentials or conflict with custom credential helpers.

Nicely summarised. So we say 401 when we do not know you, while we say 403 when we know you and do not want you to be accessing the resource. We test for both.

Just out of curiosity, do we test for these codes with other credential helpers or is this only relevant for .netrc users?

Show 28 quoted lines
> +test_expect_success 'using credentials from netrc to clone successfully' '
> +	test_when_finished clear_netrc &&
> +	set_askpass wrong &&
> +	set_netrc 127.0.0.1 user@host pass@host &&
> +	git clone "$HTTPD_URL/auth/dumb/repo.git" clone-auth-netrc &&
> +	expect_askpass none
> +'
> +
> +test_expect_success 'netrc unauthorized credentials (prompt after 401)' '
> +	test_when_finished clear_netrc &&
> +	set_askpass wrong &&
> +	set_netrc 127.0.0.1 user@host pass@wrong &&
> +	test_must_fail git clone "$HTTPD_URL/auth/dumb/repo.git" clone-auth-netrc-401 &&
> +	expect_askpass both wrong
> +'
> +
> +test_expect_success 'netrc authorized but forbidden credentials (fail on 403)' '
> +	test_when_finished clear_netrc &&
> +	set_askpass wrong &&
> +	set_netrc 127.0.0.1 forbidden-user@host pass@host &&
> +	test_must_fail git clone "$HTTPD_URL/auth/dumb/repo.git" clone-auth-netrc-403 2>err &&
> +	expect_askpass none &&
> +	grep "The requested URL returned error: 403" err
> +'
> +
>  test_expect_success 'http auth can use user/pass in URL' '
>  	set_askpass wrong &&
>  	git clone "$HTTPD_URL_USER_PASS/auth/dumb/repo.git" clone-auth-none &&
Previous: Ashlesh GawandeNext: Jeff King
Message 8 of 14 in “t5550: add netrc tests for http 401/403”
  1. t5550: add netrc tests for http 401/403Ashlesh Gawande, Jan 6, 2026
  2. Junio C HamanoJan 6, 2026
  3. Ashlesh GawandeJan 6, 2026
  4. t5550: add netrc tests for http 401/403Ashlesh Gawande, Jan 6, 2026
  5. Junio C HamanoJan 7, 2026
  6. t5550: add netrc tests for http 401/403Ashlesh Gawande, Jan 7, 2026
  7. Ashlesh GawandeJan 31, 2026
  8. Junio C HamanoFeb 6, 2026
  9. Jeff KingFeb 6, 2026
  10. Ashlesh GawandeFeb 6, 2026
  11. Ashlesh GawandeFeb 6, 2026
  12. Jeff KingFeb 6, 2026
  13. Junio C HamanoFeb 6, 2026
  14. Jeff KingFeb 6, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.