Git development
 help / color / mirror / Atom feed
From: Xavier Morel <xmo@odoo.com>
To: git@vger.kernel.org
Subject: [BUG] basic auth not send on empty password in default configuration
Date: Wed, 23 Sep 2026 09:10:11 +0200	[thread overview]
Message-ID: <6fa4c795-7f80-45e7-a42a-ee6e9cfc01cf@odoo.com> (raw)

Hit this issue playing with a custom credential helper:

- if the server requires authentication for an operation (returns 401 on
   an un-authenticated request)
- and the credential helper sets an empty username and a non-empty
   password
- the second request git sends is still un-authenticated instead of
   having basic auth set
- git then fails with an "authentication failed" error

If proactiveAuth=basic is enabled, git doesn't mind the empty username
and sends the request with basic auth set.

This was directly observed on git 2.47 and 2.55, with curl 8.5.0.

The issue seems to come from init_curl_http_auth: if the username is
unset *or empty*, it exits immediately unless proactive auth is enabled,
which matches the symptoms. From this it looks like an other workaround
would be for the credential helper to precompute the `credential` value
and return that instead of username/password, as that is guaranteed to 
be non-empty.

Either way the current behaviour is somewhat surprising as (AFAIK)
nothing in basic auth requires non-empty usernames (or even passwords),
and importantly git doesn't report anything odd except the connection
failing, the lack of auth on the second attempt is only visible when
enabling GIT_CURL_VERBOSE and comparing a successful auth with an
unsuccessful one (or on the server side, but there if the server is
bespoke one can easily chase ghosts assuming the error is obviously
somewhere in the bespoke code because select isn't broken).

                 reply	other threads:[~2026-09-23  7:10 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6fa4c795-7f80-45e7-a42a-ee6e9cfc01cf@odoo.com \
    --to=xmo@odoo.com \
    --cc=git@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox