62
static long curl_low_speed_time = -1;
63
static int curl_ftp_no_epsv;
64
static const char *curl_http_proxy;
65
+static const char *http_proxy_authmethod;
66
+static struct {
67
+ const char *name;
68
+ long curlauth_param;
69
+} proxy_authmethods[] = {
70
+ { "basic", CURLAUTH_BASIC },
71
+ { "digest", CURLAUTH_DIGEST },
72
+ { "negotiate", CURLAUTH_GSSNEGOTIATE },
73
+ { "ntlm", CURLAUTH_NTLM },
74
+#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY
75
+ { "anyauth", CURLAUTH_ANY },
76
+#endif
77
+ /*
78
+ * CURLAUTH_DIGEST_IE has no corresponding command-line option in
79
+ * curl(1) and is not included in CURLAUTH_ANY, so we leave it out
80
+ * here, too
81
+ */
82
+};
83
static const char *curl_cookie_file;
84
static int curl_save_cookies;
85
struct credential http_auth = CREDENTIAL_INIT;
274
if (!strcmp("http.proxy", var))
275
return git_config_string(&curl_http_proxy, var, value);
276
277
+ if (!strcmp("http.proxyauthmethod", var))
278
+ return git_config_string(&http_proxy_authmethod, var, value);
279
+
280
if (!strcmp("http.cookiefile", var))
281
return git_config_string(&curl_cookie_file, var, value);
282
if (!strcmp("http.savecookies", var)) {
325
#endif
326
}
327
328
+/* *var must be free-able */
329
+static void var_override(const char **var, char *value)
330
+{
331
+ if (value) {
332
+ free((void *)*var);
333
+ *var = xstrdup(value);
334
+ }
335
+}
336
+
337
+static void init_curl_proxy_auth(CURL *result)
338
+{
339
+ var_override(&http_proxy_authmethod, getenv("GIT_HTTP_PROXY_AUTHMETHOD"));
340
+
341
+#if LIBCURL_VERSION_NUM >= 0x070a07 /* CURLOPT_PROXYAUTH and CURLAUTH_ANY */
342
+ if (http_proxy_authmethod) {
343
+ int i;
344
+ for (i = 0; i < ARRAY_SIZE(proxy_authmethods); i++) {
345
+ if (!strcmp(http_proxy_authmethod, proxy_authmethods[i].name)) {
346
+ curl_easy_setopt(result, CURLOPT_PROXYAUTH,
347
+ proxy_authmethods[i].curlauth_param);
348
+ break;
349
+ }
350
+ }
351
+ if (i == ARRAY_SIZE(proxy_authmethods)) {
352
+ warning("unsupported proxy authentication method %s: using anyauth",
353
+ http_proxy_authmethod);
354
+ curl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);
355
+ }
356
+ }
357
+ else
358
+ curl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);
359
+#endif
360
+}
361
+
362
static int has_cert_password(void)
363
{
364
if (ssl_cert == NULL || ssl_cert_password_required != 1)
531
CURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);
532
#endif
533
}
479
-#if LIBCURL_VERSION_NUM >= 0x070a07
480
- curl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);
481
-#endif
534
+ init_curl_proxy_auth(result);
535
536
set_curl_keepalive(result);
537
572
if (remote && remote->http_proxy)
573
curl_http_proxy = xstrdup(remote->http_proxy);
574
575
+ if (remote)
576
+ var_override(&http_proxy_authmethod, remote->http_proxy_authmethod);
577
+
578
pragma_header = curl_slist_append(pragma_header, "Pragma: no-cache");
579
no_pragma_header = curl_slist_append(no_pragma_header, "Pragma:");
580
673
curl_http_proxy = NULL;
674
}
675
676
+ free((void *)http_proxy_authmethod);
677
+ http_proxy_authmethod = NULL;
678
+
679
if (cert_auth.password != NULL) {
680
memset(cert_auth.password, 0, strlen(cert_auth.password));
681
free(cert_auth.password);