credential-cache: respect authtype capability
Previously, credential-cache populated authtype regardless whether "get" request had authtype capability. As documented in git-credential.txt, authtype "should not be sent unless the appropriate capability ... is provided". Add test. Without this change, the test failed because "credential fill" printed an incomplete credential with only protocol and host attributes (the unexpected authtype attribute was discarded by credential.c). Signed-off-by: M Hickford <mirth.hickford@gmail.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>
M Hickford committed
Jan 9, 2025 at 22:45 UTC
0b432748507a12b92677653104b18834d83cfb10
2 files changed
+17
-2
builtin/credential-cache--daemon.c
+2
-2
@@ -141,9 +141,9 @@ static void serve_one_client(FILE *in, FILE *out)
141
fprintf(out, "username=%s\n", e->item.username);
142
if (e->item.password)
143
fprintf(out, "password=%s\n", e->item.password);
144
- if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_HELPER) && e->item.authtype)
144
+ if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_RESPONSE) && e->item.authtype)
145
fprintf(out, "authtype=%s\n", e->item.authtype);
146
- if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_HELPER) && e->item.credential)
146
+ if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_RESPONSE) && e->item.credential)
147
fprintf(out, "credential=%s\n", e->item.credential);
148
if (e->item.password_expiry_utc != TIME_MAX)
149
fprintf(out, "password_expiry_utc=%"PRItime"\n",
t/lib-credential.sh
+15
@@ -566,6 +566,21 @@ helper_test_authtype() {
566
EOF
567
'
568
569
+ test_expect_success "helper ($HELPER) gets authtype and credential only if request has authtype capability" '
570
+ check fill $HELPER <<-\EOF
571
+ protocol=https
572
+ host=git.example.com
573
+ --
574
+ protocol=https
575
+ host=git.example.com
576
+ username=askpass-username
577
+ password=askpass-password
578
+ --
579
+ askpass: Username for '\''https://git.example.com'\'':
580
+ askpass: Password for '\''https://askpass-username@git.example.com'\'':
581
+ EOF
582
+ '
583
+
584
test_expect_success "helper ($HELPER) stores authtype and credential with username" '
585
check approve $HELPER <<-\EOF
586
capability[]=authtype