docs: discuss caching personal access tokens

Describe problems storing personal access tokens in git-credential-cache and suggest alternatives. Research suggests that many users are confused about this: > the point of passwords is that (ideally) you memorise them [so] > they're never stored anywhere in plain text. Yet GitHub's personal > access token system seems to basically force you to store the token in > plain text? https://stackoverflow.com/questions/46645843/where-to-store-my-git-personal-access-token#comment89963004_46645843 Signed-off-by: M Hickford <mirth.hickford@gmail.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>

M Hickford committed Jan 10, 2025 at 22:54 UTC a90ff409f0490aef6266f17656fa626154af9715
1 file changed +17
Documentation/git-credential-cache.txt
+17
@@ -78,6 +78,23 @@ variable (this example increases the cache time to 1 hour):
78 $ git config credential.helper 'cache --timeout=3600'
79 -------------------------------------------------------
80
81 +PERSONAL ACCESS TOKENS
82 +----------------------
83 +
84 +Some remotes accept personal access tokens, which are randomly
85 +generated and hard to memorise. They typically have a lifetime of weeks
86 +or months.
87 +
88 +git-credential-cache is inherently unsuitable for persistent storage of
89 +personal access tokens. The credential will be forgotten after the cache
90 +timeout. Even if you configure a long timeout, credentials will be
91 +forgotten if the daemon dies.
92 +
93 +To avoid frequently regenerating personal access tokens, configure a
94 +credential helper with persistent storage. Alternatively, configure an
95 +OAuth credential helper to generate credentials automatically. See
96 +linkgit:gitcredentials[7], sections "Available helpers" and "OAuth".
97 +
98 GIT
99 ---
100 Part of the linkgit:git[1] suite