threads / discuss / 22438

Implement --password option for git svn perl script

Subject: Implement --password option for git svn perl script

## tl;dr

14 messages between Jan 29, 2010 and Feb 8, 2010.

replies: 13people: 5as markdown or json

Laszlo Papp· Jan 29, 2010, 14:17 UTC · lore
Hello,

It would be nice to use --pasword option on windows, like --username option with git svn facility. I can't handle SVN repository with git svn on windows if I'd like to authenticate myself with other user than the default domain name of my windows.

If I use --username option, Frank Li said me it's not enough in TortoiseGIT to provide a popup facility to type the password related to the set --username option.

What's your opinion/suggestion/recommendation ?

Best Regards, Laszlo Papp

Laszlo Papp· Jan 29, 2010, 14:18 UTC · lore

Fwd: Delivery Status Notification (Failure)

Hello,

It would be nice to use --pasword option on windows, like --username option with git svn facility. I can't handle SVN repository with git svn on windows if I'd like to authenticate myself with other user than the default domain name of my windows.

If I use --username option, Frank Li said me it's not enough in TortoiseGIT to provide a popup facility to type the password related to the set --username option.

What's your opinion/suggestion/recommendation ?

Best Regards, Laszlo Papp

Frank Li· Jan 29, 2010, 15:04 UTC · re: Laszlo Papp · lore

Re: Delivery Status Notification (Failure)

Show 5 quoted lines
>
> If I use --username option, Frank Li said me it's not enough in
> TortoiseGIT to provide a popup facility to type the password related
> to the set --username option.
>

I prefer git-svn can provide environment to launch a external application to input password like open ssh.

Laszlo Papp· Feb 1, 2010, 16:16 UTC · re: Frank Li · lore

Re: Delivery Status Notification (Failure)

On Fri, Jan 29, 2010 at 4:04 PM, Frank Li <lznuaa@gmail.com> wrote:
Show 9 quoted lines
>>
>> If I use --username option, Frank Li said me it's not enough in
>> TortoiseGIT to provide a popup facility to type the password related
>> to the set --username option.
>>
>
> I prefer git-svn can provide environment to launch a external
> application to input password like open ssh.
>
No perl guru among the volunteers if the original author is not available ? :(

Best Regards, Laszlo Papp

Tay Ray Chuan· Feb 2, 2010, 04:15 UTC · re: Frank Li · lore

Re: Delivery Status Notification (Failure)

Hi,
On Fri, Jan 29, 2010 at 11:04 PM, Frank Li <lznuaa@gmail.com> wrote:
> I prefer git-svn can provide environment to launch a external
> application to input password like open ssh.

how about users who are authenticating over http with basic and digest? How does one go about launching an external app for password input in those cases?

Please don't take this as a criticism of your personal preference. I believe this feature would make things convenient for users who want it - those who don't, nothing changes.

Even ssh (via ssh-keygen) lets you specify the passphrase at command-run time. Others include htpasswd, htdigest...

-- 
Cheers,
Ray Chuan
Frank Li· Feb 2, 2010, 04:30 UTC · re: Tay Ray Chuan · lore

Re: Delivery Status Notification (Failure)

2010/2/2 Tay Ray Chuan <rctay89@gmail.com>:
Show 9 quoted lines
> Hi,
>
> On Fri, Jan 29, 2010 at 11:04 PM, Frank Li <lznuaa@gmail.com> wrote:
>> I prefer git-svn can provide environment to launch a external
>> application to input password like open ssh.
>
> how about users who are authenticating over http with basic and
> digest? How does one go about launching an external app for password
> input in those cases?

There are not problem if run git svn clone from console. But a gui application, such tortoisegit, launch "git svn clone" and capture git svn clone output. If passwd needed, git svn clone will read character from console but GUI application don't know that and wait git svn output. So there are dead lock till timeout and fail.

The same problem has been happen at ssh. But OpenSSH provide a option, environment SSH_ASKPASS, which point to a application. when passwd need, openssh launch this GUI application, user can input passwd at this GUI application.

The basic requirement is git svn can provide a way to prompt a dialog box to input passwd.

Frank Li
Laszlo Papp· Feb 2, 2010, 06:37 UTC · re: Frank Li · lore

Re: Delivery Status Notification (Failure)

> The basic requirement is git svn can provide a way to prompt a dialog
> box to input passwd.

Yeah, it's a very basic use case, but I don't know whether there is a workaround for it somehow, maybe perl gurus or git svn users could help more...

My company, where there are windows users (95% of the company), would like to use TortoiseGIT as a graphical client for SVN server repositories as an SVN client, no other way by us, so it'd be high priority :) So I've got a beer for any volunteer, thanks :P

Best Regards, Laszlo Papp

Eric Wong· Feb 2, 2010, 09:05 UTC · re: Laszlo Papp · lore

Re: Implement --password option for git svn perl script

Laszlo Papp <djszapi@archlinux.us> wrote:
Show 11 quoted lines
> > The basic requirement is git svn can provide a way to prompt a dialog
> > box to input passwd.
> 
> Yeah, it's a very basic use case, but I don't know whether there is a
> workaround for it somehow, maybe perl gurus or git svn users could
> help more...
> 
> My company, where there are windows users (95% of the company), would
> like to use TortoiseGIT as a graphical client for SVN server
> repositories as an SVN client, no other way by us, so it'd be high
> priority :) So I've got a beer for any volunteer, thanks :P
Hi, (fixed subject so I don't mistake it for junk again)

I don't know (and have no way to test) how to deal with input dialogs for reading a password on Windows (nor any sort of IPC). Somebody else will have to implement it.

Having a --password option in the command line could work, but it's painfully insecure if there's any way for another regular user to view the process table. Not something I'd like to encourage...

Since SVN already caches passwords in a mostly secure location on disk (at least on *nix), shouldn't git svn be able to use the password cache SVN uses?

-- 
Eric Wong
Frank Li· Feb 2, 2010, 09:18 UTC · re: Eric Wong · lore

Re: Implement --password option for git svn perl script

> Having a --password option in the command line could work, but it's
> painfully insecure if there's any way for another regular user to view
> the process table.  Not something I'd like to encourage...
>
Yes, it is insecure. "--password" seam undocumented.
Show 7 quoted lines
> Since SVN already caches passwords in a mostly secure location on disk
> (at least on *nix), shouldn't git svn be able to use the password cache
> SVN uses?
>
> --
> Eric Wong
>
Laszlo Papp· Feb 2, 2010, 13:16 UTC · re: Eric Wong · lore

Re: Implement --password option for git svn perl script

> Since SVN already caches passwords in a mostly secure location on disk
> (at least on *nix), shouldn't git svn be able to use the password cache
> SVN uses?

@Frank Li @Eric Wong

Maybe you can check whether how TortoiseSVN or SVN client code handle this situation, because it's the same server, but 'just' the client side is different a little bit, but the same situation happen there in case TortoiseSVN a popup menu appears when you try to authenticate yourself.

Second way is to ask on the SVN mailing list, how they use it, or maybe I'm totally wrong with it :P

Best Regards, Laszlo Papp

Frank Li· Feb 2, 2010, 23:47 UTC · re: Laszlo Papp · lore

Re: Implement --password option for git svn perl script

Is it possible use OpenSSH method to let GUI to input passwd. environment SSH_ASKPASS, which point to a application. when passwd need, openssh launch this GUI application, user can input passwd at this GUI application.

Laszlo Papp· Feb 4, 2010, 07:45 UTC · re: Frank Li · lore

Re: Implement --password option for git svn perl script

On Wed, Feb 3, 2010 at 12:47 AM, Frank Li <lznuaa@gmail.com> wrote:
Show 5 quoted lines
> Is it possible use OpenSSH method to let GUI to input passwd.
> environment SSH_ASKPASS, which point to a application. when
> passwd need, openssh launch this GUI application,  user can input
> passwd at this GUI application.
>

What do you mean ? Should I install TortoiseGIT with openssh client, so should I need to choose this option from the 2 facilities ?

Best Regards, Laszlo Papp

Steve Diver· Feb 5, 2010, 23:01 UTC · re: Eric Wong · lore

Re: Implement --password option for git svn perl script

On 02/02/2010 09:05, Eric Wong wrote:
Show 28 quoted lines
>
> Laszlo Papp<djszapi@archlinux.us>  wrote:
>>> The basic requirement is git svn can provide a way to prompt a dialog
>>> box to input passwd.
>>
>> Yeah, it's a very basic use case, but I don't know whether there is a
>> workaround for it somehow, maybe perl gurus or git svn users could
>> help more...
>>
>> My company, where there are windows users (95% of the company), would
>> like to use TortoiseGIT as a graphical client for SVN server
>> repositories as an SVN client, no other way by us, so it'd be high
>> priority :) So I've got a beer for any volunteer, thanks :P
>
> Hi, (fixed subject so I don't mistake it for junk again)
>
> I don't know (and have no way to test) how to deal with input dialogs
> for reading a password on Windows (nor any sort of IPC).  Somebody else
> will have to implement it.
>
> Having a --password option in the command line could work, but it's
> painfully insecure if there's any way for another regular user to view
> the process table.  Not something I'd like to encourage...
>
> Since SVN already caches passwords in a mostly secure location on disk
> (at least on *nix), shouldn't git svn be able to use the password cache
> SVN uses?
>

Tortoise, along with at least one other Windows GUI utilizes the Putty suite as a helper app for key chain and password handling, and needs to be loaded prior to any SSH operations. Tortoise have gone so far as to rewrite plink (Tortoiseplink.exe)so that that a prompt for the password is given, but this is undocumented AFAIK.

Otherwise, it is an unfortunate fact that a DOS console session is invoked whenever openSSH is used. For the average Windows user this is a scary occurrence, and is one of the obstacles that prevents wider casual take up of Git on Windows IMHO.

I understand that it comes down to a problem with communication between a dialogue and an SSH client via STDOUT. I believe Dscho might have some insight into this as it is a recurrent topic on the MsysGit tracker.

Steve

← back to recent threads