threads / discuss / 43861

Credential helpers processing order

Subject: Credential helpers processing order

## tl;dr

3 messages between Aug 16, 2016 and Aug 16, 2016.

replies: 2people: 3as markdown or json

Dmitry Neverov· Aug 16, 2016, 15:13 UTC · lore
Hi,

I wonder why credential helpers are called in the order: system, global, local, command-line and not in the reverse order? This make it impossible to provide a custom helper and disable default ones via command-line parameter. My use-case is to clone a repository in a non-interactive environment where a system-level GUI helper is configured: clone hangs since system-level helper called first and there is no input from the user. Also if a system-level helper sets quit=true, then lower-level helpers won't be called at all. Is it by design?

-- Dmitry

Jacob Keller· Aug 16, 2016, 15:58 UTC · re: Dmitry Neverov · lore

Re: Credential helpers processing order

On Tue, Aug 16, 2016 at 8:13 AM, Dmitry Neverov <dmitry.neverov@gmail.com> wrote:

Show 12 quoted lines
> Hi,
>
> I wonder why credential helpers are called in the order: system,
> global, local, command-line and not in the reverse order? This make it
> impossible to provide a custom helper and disable default ones via
> command-line parameter. My use-case is to clone a repository in a
> non-interactive environment where a system-level GUI helper is
> configured: clone hangs since system-level helper called first and
> there is no input from the user. Also if a system-level helper sets
> quit=true, then lower-level helpers won't be called at all. Is it by
> design?
>

If I understand correctly, the credential helpers aren't supposed to require input so it is assumed they can be tried in sequence if one fails? It might make sense to reverse the order though...

Thanks, Jake

Show 6 quoted lines
> --
> Dmitry
> --
> To unsubscribe from this list: send the line "unsubscribe git" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
Jeff King· Aug 16, 2016, 16:12 UTC · re: Dmitry Neverov · lore

Re: Credential helpers processing order

On Tue, Aug 16, 2016 at 05:13:55PM +0200, Dmitry Neverov wrote:
Show 9 quoted lines
> I wonder why credential helpers are called in the order: system,
> global, local, command-line and not in the reverse order? This make it
> impossible to provide a custom helper and disable default ones via
> command-line parameter. My use-case is to clone a repository in a
> non-interactive environment where a system-level GUI helper is
> configured: clone hangs since system-level helper called first and
> there is no input from the user. Also if a system-level helper sets
> quit=true, then lower-level helpers won't be called at all. Is it by
> design?

I agree that it's not really a sensible order. But reversing them isn't quite right either. The problem is that the config code just gives the credential code a sequence of items, with no indication which file they came from, with what priority, etc.

For config keys with a single value, "last one wins" makes sense; we just keep overwriting the previous value.

But for lists (like credential.helper, but also other things like remote.*.fetch), we just build up the list. And we can't tell the difference between two items next to each in the same file, or two in different files with differing priorities.

Fixing that would be tricky. But I think for your case (and most similar cases), you'd be happy to just be able to "reset" the list to empty. As of git v2.9.0, you can do that, like so:

  [credential]
  helper = "!echo >&2 should not run;:"
  helper =
  helper = "!echo >&2 should run;:"
-Peff

← back to recent threads