git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git remote origin leaks user access token

From
Junio C Hamano <gitster@pobox.com>
Date
Jul 1, 2024, 19:04 UTC
Message-ID
<xmqqsewtvsrg.fsf@gitster.g>
In-Reply-To
<ZoLY_yxpQBjmp8O3@tapette.crustytoothpaste.net>
"brian m. carlson" <sandals@crustytoothpaste.net> writes:
Show 17 quoted lines
> I'll point out that we already document this in the Git FAQ (git help
> gitfaq):
>
> ----
> How do I specify my credentials when pushing over HTTP?
> ...
>
> We also have a FAQ entry about how to read credentials from the
> environment as well, since that's a common thing people want to do.
> ...
>
> I do want to point out that several people, not just me, have worked
> together to make using a credential helper as easy and robust as
> possible.  I mention this not to contradict Jonathan, who I think is
> also trying to help in this regard, but mostly to mention that as a
> project we've been trying to gently nudge people into doing the more
> secure thing.
Two and a half things.
 - Perhaps we want to explicitly single out URLs that embed
   credential in the documentation and tell readers not to use that.
   I wonder if it would be possible to deprecate the support of such
   URLs over time.
 - The original talks about "malicious tool runs "git remote get-url
   ..." but if you let malicious tools to run as your self, you can
   easily steal the credential out of system keychain as well, so
   "do not let malicious things to run as/for you---they will do
   malicious things to you" may be a good general advice.  Those who
   need that kind of advice would not be helped all that much by
   moving away from using URLs that embed credential and instead
   start using credential helpers.
Thanks.
    
Previous: Jeff King
Message 6 of 6 in “Re: Git remote origin leaks user access token”
  1. Jonathan NiederJul 1, 2024
  2. brian m. carlsonJul 1, 2024
  3. Jeff KingJul 1, 2024
  4. H. Peter AnvinJul 2, 2024
  5. Jeff KingJul 2, 2024
  6. Junio C HamanoJul 1, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.