git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/3] Add config option/env var to limit HTTP auth methods

From
Junio C Hamano <gitster@pobox.com>
Date
May 13, 2022, 20:26 UTC
Message-ID
<xmqqzgjl89i6.fsf@gitster.g>
In-Reply-To
<20220513070416.37235-3-Simon.Richter@hogyros.de>
Simon.Richter@hogyros.de writes:
Show 18 quoted lines
> +http.authMethod::
> +	Set the method with which to authenticate to the HTTP server, if
> +	required. This can be overridden on a per-remote basis; see
> +	`remote.<name>.authMethod`. Both can be overridden by the
> +	`GIT_HTTP_AUTHMETHOD` environment variable.  Possible values are:
> ++
> +--
> +* `anyauth` - Automatically pick a suitable authentication method. It is
> +  assumed that the server answers an unauthenticated request with a 401
> +  status code and one or more WWW-Authenticate headers with supported
> +  authentication methods. This is the default.
> +* `basic` - HTTP Basic authentication
> +* `digest` - HTTP Digest authentication; this prevents the password from being
> +  transmitted to the server in clear text
> +* `negotiate` - GSS-Negotiate authentication (compare the --negotiate option
> +  of `curl(1)`)
> +* `ntlm` - NTLM authentication (compare the --ntlm option of `curl(1)`)
> +--
The above makes sense.

Configuring this variable per URL, just like all other variables in "http.*" namespace, we should be able to use the "http.<url>.*" mechanism that the users are already familiar with.

Show 11 quoted lines
> diff --git a/Documentation/config/remote.txt b/Documentation/config/remote.txt
> index 0678b4bcfe..0f87234427 100644
> --- a/Documentation/config/remote.txt
> +++ b/Documentation/config/remote.txt
> @@ -10,6 +10,10 @@ remote.<name>.url::
>  remote.<name>.pushurl::
>  	The push URL of a remote repository.  See linkgit:git-push[1].
>  
> +remote.<name>.authMethod::
> +	For http and https remotes, the method to use for
> +	authenticating against the server. See `http.authMethod`.
IOW, this looks out of place.
Previous: simon.richter@hogyros.de
Message 7 of 7 in “Allow configuration of HTTP authentication method”
  1. 0/3 Allow configuration of HTTP authentication methodsimon.richter@hogyros.de, May 13, 2022
  2. 3/3 Allow empty user name in HTTP authenticationsimon.richter@hogyros.de, May 13, 2022
  3. brian m. carlsonMay 13, 2022
  4. 1/3 Rename proxy_authmethods -> authmethodssimon.richter@hogyros.de, May 13, 2022
  5. Junio C HamanoMay 13, 2022
  6. 2/3 Add config option/env var to limit HTTP auth methodssimon.richter@hogyros.de, May 13, 2022
  7. Junio C HamanoMay 13, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.