threads / patch / 18669

patchAllow any HTTP authentication scheme, not only basic

Subject: [PATCH] Allow any HTTP authentication scheme, not only basic

## tl;dr

4 messages between Mar 31, 2009 and Apr 1, 2009. Diffs are folded; open one to read it.

replies: 3people: 2as markdown or json

Martin Storsjo· Mar 31, 2009, 17:31 UTC · lore
Signed-off-by: Martin Storsjo <martin@martin.st>
---
 http.c |    1 +
 1 files changed, 1 insertions(+), 0 deletions(-)
Show changes to http.c +1 −0
diff --git a/http.c b/http.c
index 2fc55d6..7cb53e8 100644
--- a/http.c
+++ b/http.c
@@ -165,6 +165,7 @@ static CURL *get_curl_handle(void)
 #if LIBCURL_VERSION_NUM >= 0x070907
 	curl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);
 #endif
+	curl_easy_setopt(result, CURLOPT_HTTPAUTH, CURLAUTH_ANY);
 
 	init_curl_http_auth(result);
 
-- 
1.6.0.2
Martin Storsjo· Mar 31, 2009, 18:54 UTC · re: Martin Storsjo · lore
Signed-off-by: Martin Storsjo <martin@martin.st>
---
Updated patch, enable only on libcurl versions new enough
 http.c |    3 +++
 1 files changed, 3 insertions(+), 0 deletions(-)
Show changes to http.c +3 −0
diff --git a/http.c b/http.c
index 2fc55d6..eae74aa 100644
--- a/http.c
+++ b/http.c
@@ -165,6 +165,9 @@ static CURL *get_curl_handle(void)
 #if LIBCURL_VERSION_NUM >= 0x070907
 	curl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);
 #endif
+#if LIBCURL_VERSION_NUM >= 0x070a06
+	curl_easy_setopt(result, CURLOPT_HTTPAUTH, CURLAUTH_ANY);
+#endif
 
 	init_curl_http_auth(result);
 
-- 
1.6.0.2
Johannes Schindelin· Mar 31, 2009, 19:04 UTC · re: Martin Storsjo · lore

Re: [PATCH] Allow any HTTP authentication scheme, not only basic

Hi,
On Tue, 31 Mar 2009, Martin Storsjo wrote:
> Updated patch, enable only on libcurl versions new enough

Heh, you beat me to looking up from which version onward curl supports this...

Thanks! Dscho

Martin Storsjö· Apr 1, 2009, 15:06 UTC · re: Johannes Schindelin · lore

Re: [PATCH] Allow any HTTP authentication scheme, not only basic

Hi,
My patch doesn't seem to come completely without troubles, though.

I still find this a potentially valuable scenario; e.g. for a public repo with push access only over HTTP, but using secure digest authentication instead of sending the credentials in plaintext.

One downside is that it causes a lot more HTTP requests, since libcurl initially tries without any authentication for (almost?) every request, doubling the number of requests made.

Fetching works just fine, but pushing may fail on auth problems in some cases where it wouldn't fail otherwise, if only basic authentication was used and libcurl automatically used that without probing what authentication scheme the server uses.

Things generally seem to work fine with Apache, but with Lighttpd, retrying with proper credentials may fail due to CURLE_SEND_FAIL_REWIND /* 65 - Sending the data requires a rewind that failed */. This issue can be fixed by another patch (that I'll send soon).

Even after fixing that, there still seems to be some issues on some older curl versions; in particular, 7.16.3, shipped in OS X Leopard, returns error code CURLE_HTTP_RETURNED_ERROR instead of retrying properly with authentication.

// Martin

← back to recent threads