# Credential helpers processing order

3 messages from 2016-08-16 to 2016-08-16. Participants: Dmitry Neverov, Jacob Keller, Jeff King.
Thread: https://gitlist.dev/t/43861

## Dmitry Neverov, 2016-08-16 15:13

Subject: Credential helpers processing order
Message-ID: <CAC+L6n0j0=6haBprM2ip75=orEi_5oBedHV1iPBTgi-N8Y6=4A@mail.gmail.com>
URL: https://gitlist.dev/e/CAC%2BL6n0j0%3D6haBprM2ip75%3DorEi_5oBedHV1iPBTgi-N8Y6%3D4A%40mail.gmail.com

```
Hi,

I wonder why credential helpers are called in the order: system,
global, local, command-line and not in the reverse order? This make it
impossible to provide a custom helper and disable default ones via
command-line parameter. My use-case is to clone a repository in a
non-interactive environment where a system-level GUI helper is
configured: clone hangs since system-level helper called first and
there is no input from the user. Also if a system-level helper sets
quit=true, then lower-level helpers won't be called at all. Is it by
design?

--
Dmitry

```

## Jacob Keller, 2016-08-16 15:58

Subject: Re: Credential helpers processing order
Message-ID: <CA+P7+xpe2FeBjO0AEHTyuZPEOpCUmt=vUcs5RFYhE9KTZWLNhw@mail.gmail.com>
URL: https://gitlist.dev/e/CA%2BP7%2Bxpe2FeBjO0AEHTyuZPEOpCUmt%3DvUcs5RFYhE9KTZWLNhw%40mail.gmail.com
In-Reply-To: <CAC+L6n0j0=6haBprM2ip75=orEi_5oBedHV1iPBTgi-N8Y6=4A@mail.gmail.com>

```
On Tue, Aug 16, 2016 at 8:13 AM, Dmitry Neverov
<dmitry.neverov@gmail.com> wrote:
> Hi,
>
> I wonder why credential helpers are called in the order: system,
> global, local, command-line and not in the reverse order? This make it
> impossible to provide a custom helper and disable default ones via
> command-line parameter. My use-case is to clone a repository in a
> non-interactive environment where a system-level GUI helper is
> configured: clone hangs since system-level helper called first and
> there is no input from the user. Also if a system-level helper sets
> quit=true, then lower-level helpers won't be called at all. Is it by
> design?
>

If I understand correctly, the credential helpers aren't supposed to
require input so it is assumed they can be tried in sequence if one
fails? It might make sense to reverse the order though...

Thanks,
Jake

> --
> Dmitry
> --
> To unsubscribe from this list: send the line "unsubscribe git" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html

```

## Jeff King, 2016-08-16 16:12

Subject: Re: Credential helpers processing order
Message-ID: <20160816161216.xva2f2lp53u57bo4@sigill.intra.peff.net>
URL: https://gitlist.dev/e/20160816161216.xva2f2lp53u57bo4%40sigill.intra.peff.net
In-Reply-To: <CAC+L6n0j0=6haBprM2ip75=orEi_5oBedHV1iPBTgi-N8Y6=4A@mail.gmail.com>

```
On Tue, Aug 16, 2016 at 05:13:55PM +0200, Dmitry Neverov wrote:

> I wonder why credential helpers are called in the order: system,
> global, local, command-line and not in the reverse order? This make it
> impossible to provide a custom helper and disable default ones via
> command-line parameter. My use-case is to clone a repository in a
> non-interactive environment where a system-level GUI helper is
> configured: clone hangs since system-level helper called first and
> there is no input from the user. Also if a system-level helper sets
> quit=true, then lower-level helpers won't be called at all. Is it by
> design?

I agree that it's not really a sensible order. But reversing them isn't
quite right either. The problem is that the config code just gives the
credential code a sequence of items, with no indication which file they
came from, with what priority, etc.

For config keys with a single value, "last one wins" makes sense; we
just keep overwriting the previous value.

But for lists (like credential.helper, but also other things like
remote.*.fetch), we just build up the list. And we can't tell the
difference between two items next to each in the same file, or two in
different files with differing priorities.

Fixing that would be tricky. But I think for your case (and most similar
cases), you'd be happy to just be able to "reset" the list to empty. As
of git v2.9.0, you can do that, like so:

  [credential]
  helper = "!echo >&2 should not run;:"
  helper =
  helper = "!echo >&2 should run;:"

-Peff

```
