From: Jonathan Tan <jonathantanmy@google.com>
To: git@vger.kernel.org
Cc: Jonathan Tan <jonathantanmy@google.com>,
sandals@crustytoothpaste.net, gitster@pobox.com, peff@peff.net
Subject: [PATCH v2 0/3] Safer GIT_CURL_VERBOSE
Date: Wed, 13 May 2020 12:12:45 -0700 [thread overview]
Message-ID: <cover.1589394456.git.jonathantanmy@google.com> (raw)
In-Reply-To: <cover.1589218693.git.jonathantanmy@google.com>
Thanks everyone. I went ahead with GIT_REDACT_AUTHORIZATION to match
GIT_REDACT_COOKIES, with the default being true (i.e. you need to set it
to "0" to have behavior change).
An alternative is to name it as non-authorization-specific, e.g.
GIT_TRACE_REDACT, as suggested by others. But as far as I can tell, we
currently only redact auth (by default) and cookies (opt-in, since we
need the user to tell us exactly which cookies to redact), so it seems
better to me to have auth redaction be a peer to cookie redaction,
rather than being controlled by a flag that controls everything.
Jonathan Tan (3):
t5551: test that GIT_TRACE_CURL redacts password
http: make GIT_TRACE_CURL auth redaction optional
http, imap-send: stop using CURLOPT_VERBOSE
Documentation/git.txt | 8 +++++--
http.c | 19 ++++++++++++---
http.h | 7 ++++++
imap-send.c | 2 +-
t/t5551-http-fetch-smart.sh | 46 ++++++++++++++++++++++++++++++++++++
t/t5581-http-curl-verbose.sh | 2 +-
trace.c | 20 ++++++++++++----
trace.h | 6 +++++
8 files changed, 99 insertions(+), 11 deletions(-)
Range-diff against v1:
-: ---------- > 1: 8c70a45b24 http: make GIT_TRACE_CURL auth redaction optional
1: 1df9e9deb7 ! 2: f5a29e8fa1 http, imap-send: stop using CURLOPT_VERBOSE
@@ imap-send.c: static CURL *setup_curl(struct imap_server_conf *srvc, struct crede
return curl;
## t/t5551-http-fetch-smart.sh ##
-@@ t/t5551-http-fetch-smart.sh: test_expect_success 'GIT_TRACE_CURL redacts auth details' '
- grep "Authorization: Basic <redacted>" trace
+@@ t/t5551-http-fetch-smart.sh: test_expect_success 'GIT_TRACE_CURL does not redact auth details if GIT_REDACT_A
+ grep "Authorization: Basic [0-9a-zA-Z+/]" trace
'
+test_expect_success 'GIT_CURL_VERBOSE redacts auth details' '
--
2.26.2.645.ge9eca65c58-goog
next prev parent reply other threads:[~2020-05-13 19:12 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-05-11 17:43 [PATCH 0/2] Safer GIT_CURL_VERBOSE Jonathan Tan
2020-05-11 17:43 ` [PATCH 1/2] t5551: test that GIT_TRACE_CURL redacts password Jonathan Tan
2020-05-12 19:08 ` Jeff King
2020-05-11 17:43 ` [PATCH 2/2] http, imap-send: stop using CURLOPT_VERBOSE Jonathan Tan
2020-05-12 19:16 ` Jeff King
2020-05-12 19:23 ` Jonathan Tan
2020-05-12 19:27 ` Jeff King
2020-05-12 23:13 ` brian m. carlson
2020-05-13 0:10 ` Junio C Hamano
2020-05-13 4:50 ` Jeff King
2020-05-13 5:05 ` Junio C Hamano
2020-05-13 6:16 ` Daniel Stenberg
2020-05-13 14:45 ` Jeff King
2020-05-13 19:12 ` Jonathan Tan [this message]
2020-05-13 19:12 ` [PATCH v2 1/3] t5551: test that GIT_TRACE_CURL redacts password Jonathan Tan
2020-05-13 19:12 ` [PATCH v2 2/3] http: make GIT_TRACE_CURL auth redaction optional Jonathan Tan
2020-05-13 19:29 ` Junio C Hamano
2020-05-13 19:12 ` [PATCH v2 3/3] http, imap-send: stop using CURLOPT_VERBOSE Jonathan Tan
2020-05-13 19:27 ` [PATCH v2 0/3] Safer GIT_CURL_VERBOSE Junio C Hamano
2020-05-13 19:33 ` Junio C Hamano
2020-05-15 20:47 ` Jeff King
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cover.1589394456.git.jonathantanmy@google.com \
--to=jonathantanmy@google.com \
--cc=git@vger.kernel.org \
--cc=gitster@pobox.com \
--cc=peff@peff.net \
--cc=sandals@crustytoothpaste.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).