Skip to content
Open
Show file tree
Hide file tree
Changes from 2 commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
be2b0a8
compat/posix: introduce utimensat(2) wrapper
vonosmas Aug 21, 2026
2c8ab1a
treewide: use utimensat(2) instead of legacy utime(3p)
vonosmas Aug 21, 2026
ae977d6
compat/posix: drop legacy <utime.h> header and shims
vonosmas Aug 21, 2026
dc78849
Merge branch 'kh/doc-datamodel' into ta/command-list-guides-sync-lint
gitster Sep 10, 2026
31ab709
command-list.txt: add gitformat-loose(5) and gitpacking(7)
taahol Sep 10, 2026
4ce144a
lint-docs: check the guide list in command-list.txt
taahol Sep 10, 2026
25f7f09
merge-ll: use strbuf to read back external merge result
peff Sep 11, 2026
5c86262
merge-ll: catch close() errors when writing external tempfiles
peff Sep 11, 2026
2aaf186
merge-ll: use tempfile API for external driver files
peff Sep 11, 2026
1847b18
Merge branch 'ps/odb-alternates-at-creation' into jch
gitster Sep 17, 2026
ba8defa
Merge branch 'hn/history-squash' into jch
gitster Sep 17, 2026
e0cd7bd
Merge branch 'kn/receive-report-hook' into jch
gitster Sep 17, 2026
10957a1
Merge branch 'jc/cocci-free-updates' into jch
gitster Sep 17, 2026
608bf29
Merge branch 'ak/refs-files-root-ref-lock' into jch
gitster Sep 17, 2026
fdb8395
Merge branch 'ps/ref-storage-format' into jch
gitster Sep 17, 2026
9aba6cb
Merge branch 'dk/use-nsec-runtime' into jch
gitster Sep 17, 2026
89dee53
### match next
gitster Sep 17, 2026
31bbc25
Merge branch 'ij/subtree-reject-v2-config' into jch
gitster Sep 17, 2026
aa65892
Merge branch 'ap/http-preserve-wwwauth-redirect' into jch
gitster Sep 17, 2026
a840457
Merge branch 'as/utimensat-utimes' into jch
gitster Sep 17, 2026
d5b21c5
Merge branch 'vv/branch-recurse-no-start-ref' into jch
gitster Sep 17, 2026
5335aa4
Merge branch 'dw/config-read-both-global' into jch
gitster Sep 17, 2026
61d2fe4
Merge branch 'ta/command-list-guides-sync-lint' into jch
gitster Sep 17, 2026
cf22773
Merge branch 'jk/merge-ll-tempfile-cleanup' into jch
gitster Sep 17, 2026
50e9875
Merge branch 'pp/midx-write-skip-empty' into jch
gitster Sep 17, 2026
9f5e444
Merge branch 'hn/range-diff-matched-only' into jch
gitster Sep 17, 2026
aa7921d
Update main.yml
kaykecrystian261-max Sep 17, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions credential.c
Original file line number Diff line number Diff line change
Expand Up @@ -708,3 +708,19 @@ void credential_from_url(struct credential *c, const char *url)
if (credential_from_url_gently(c, url, 0) < 0)
die(_("credential url cannot be parsed: %s"), url);
}

void credential_update_url(struct credential *c, const char *url)
{
struct strvec wwwauth_headers = STRVEC_INIT;

/*
* credential_from_url() clears the whole credential. Preserve the
* WWW-Authenticate list, which is derived from the server's original
* response rather than from the URL and is required to authenticate to
* the new URL.
*/
SWAP(wwwauth_headers, c->wwwauth_headers);
credential_from_url(c, url);
SWAP(c->wwwauth_headers, wwwauth_headers);
strvec_clear(&wwwauth_headers);
}
8 changes: 8 additions & 0 deletions credential.h
Original file line number Diff line number Diff line change
Expand Up @@ -305,6 +305,14 @@ void credential_write(const struct credential *, FILE *,
void credential_from_url(struct credential *, const char *url);
int credential_from_url_gently(struct credential *, const char *url, int quiet);

/*
* Update the URL-derived fields (protocol, host, path) of an existing
* credential to match a new URL. Unlike credential_from_url(), this function
* preserves state that was derived from a server's HTTP redirect response,
* such as the WWW-Authenticate headers.
*/
void credential_update_url(struct credential *c, const char *url);

int credential_match(const struct credential *want,
const struct credential *have, int match_password);

Expand Down
9 changes: 8 additions & 1 deletion http.c
Original file line number Diff line number Diff line change
Expand Up @@ -2429,7 +2429,14 @@ static int http_request_recoverable(const char *url,
if (options->effective_url && options->base_url) {
if (update_url_from_redirect(options->base_url,
url, options->effective_url)) {
credential_from_url(&http_auth, options->base_url->buf);
/*
* Use credential_update_url() rather than
* credential_from_url() so that the WWW-Authenticate
* challenge the server sent with the redirect target's
* response is preserved and handed to the credential
* helper.
*/
credential_update_url(&http_auth, options->base_url->buf);
url = options->effective_url->buf;
}
}
Expand Down
1 change: 1 addition & 0 deletions t/lib-httpd/apache.conf
Original file line number Diff line number Diff line change
Expand Up @@ -203,6 +203,7 @@ RewriteRule ^/dumb-redir/(.*)$ /dumb/$1 [R=301]
RewriteRule ^/smart-redir-perm/(.*)$ /smart/$1 [R=301]
RewriteRule ^/smart-redir-temp/(.*)$ /smart/$1 [R=302]
RewriteRule ^/smart-redir-auth/(.*)$ /auth/smart/$1 [R=301]
RewriteRule ^/custom_auth_redir/(.*)$ /custom_auth/$1 [R=302]
RewriteRule ^/smart-redir-limited/(.*)/info/refs$ /smart/$1/info/refs [R=301]
RewriteRule ^/ftp-redir/(.*)$ ftp://localhost:1000/$1 [R=302]

Expand Down
45 changes: 45 additions & 0 deletions t/t5563-simple-http-auth.sh
Original file line number Diff line number Diff line change
Expand Up @@ -557,6 +557,51 @@ test_expect_success 'access using bearer auth' '
EOF
'

test_expect_success 'bearer auth after redirect preserves wwwauth headers' '
test_when_finished "per_test_cleanup" &&

set_credential_reply get <<-EOF &&
capability[]=authtype
authtype=Bearer
credential=YS1naXQtdG9rZW4=
EOF

cat >"$HTTPD_ROOT_PATH/custom-auth.valid" <<-EOF &&
id=1 creds=Bearer YS1naXQtdG9rZW4=
EOF

cat >"$HTTPD_ROOT_PATH/custom-auth.challenge" <<-EOF &&
id=1 status=200
id=default response=WWW-Authenticate: FooBar param1="value1" param2="value2"
id=default response=WWW-Authenticate: Bearer authorize_uri="id.example.com" p=1 q=0
id=default response=WWW-Authenticate: Basic realm="example.com"
EOF

test_config_global credential.helper test-helper &&
test_config_global credential.useHttpPath true &&
git ls-remote "$HTTPD_URL/custom_auth_redir/repo.git" &&

expect_credential_query get <<-EOF &&
capability[]=authtype
capability[]=state
protocol=http
host=$HTTPD_DEST
path=custom_auth/repo.git
wwwauth[]=FooBar param1="value1" param2="value2"
wwwauth[]=Bearer authorize_uri="id.example.com" p=1 q=0
wwwauth[]=Basic realm="example.com"
EOF

expect_credential_query store <<-EOF
capability[]=authtype
authtype=Bearer
credential=YS1naXQtdG9rZW4=
protocol=http
host=$HTTPD_DEST
path=custom_auth/repo.git
EOF
'

test_expect_success 'access using bearer auth with invalid credentials' '
test_when_finished "per_test_cleanup" &&

Expand Down