Repository navigation
Document where authentication credentials are stored #1773
Description
Activity
@raiskila Have you tried
gh auth status?$ gh auth status github.com ✓ Logged in to github.com as mislav (~/.config/gh/hosts.yml) ✓ Git operations for github.com configured to use https protocol.The authentication credentials are stored in
~/.config/gh/hosts.yml.Good points about documentation; thank you!
Reacted by Nuru, Angelofdeath6911, Cameron Smith, Vincent G, R S, Dixon Sean Low Yan Feng, Chinarut, udance4ever, Marek, ttd and 1 moreThanks for pointing that out, I was on 0.9.0 due to outdated Homebrew formulas and
gh auth statuswas missing.Yeah, this was mostly about the documentation, but I'm glad the information is also available there!
@mislav Hi there, I was taking a look at this issue but I couldn't find where the documentation should be. I am guessing https://cli.github.com/manual/gh_auth_status here but even if that's the right place I don't see where or how the project is generating the documentation. If you could point me in the right direction I can help out with the change. Thanks 🙇
@cored Our documentation pages are autogenerated by spf13/cobra during our release workflow. As for where we actually want this documentation to be placed I think we should wait for @mislav to chime in on that.
Reacted by Rafael George and Max BaylisWhere would you like that directory to be?
Please document clearly where sensitive information is stored, and whether or not it is stored in plain text form. For example, it appears
.config/gh/hosts.ymlcontains sensitive authentication tokens that should be protected.Reacted by seph, Gibson Fahnestock, Steve Ruble, Richard Bullington-McGuire, Zoltán Reegn, Kyle W. Rader, Isaac Joseph, Chris Stuart Parry, Marek, Markus Eicher and 2 moreFor example, it appears .config/gh/hosts.yml contains sensitive authentication tokens that should be protected.
For this bit specifically, see #449
Fwiw, I'd expect to be able to find the information by looking here: https://cli.github.com/manual/gh_config
Remember, users don't know a system when they're looking for answers. The actual answer can be stored in
gh status, but it'd be really valuable to include asee alsoreference fromgh config.Reacted by Kyle W. Rader, wileyhy and Nicholas BRelated question: It is unclear to me if trying to configure SSH auth is going to wipe-out my existing ssh authentication for Git. I already have an ssh key generated, and uploaded to Github, but the
gh auth logincommand seems to ignore that there's already a key there and still wants to log in via web browser.Does this warrant a new issue specifically to allow using existing ssh configurations?
@kyle-rader
ghis trying to log in via a web browser in order to get an oauth token it can use to call the GitHub API; it's a different authentication than the SSH key used forgitoperations. If you answer "no" toghsetting upgitauth for you and selectsshas your preferredgitprotocol, your existing SSH key will continue to work normally forgitoperations.Reacted by Kyle W. Rader and Gene Wood@vilmibm thanks for clarifying Nate, this makes sense. I take it github just doesn't support ssh auth for their web api? Only the git endpoints?
@kyle-rader correct.
Fwiw, I'd expect to be able to find the information by looking here: https://cli.github.com/manual/gh_config
@jsoref, I think it would also make sense to put the information in
gh auth login. Because this command is what is storing the credentials. I think it should also explain the config it is doing or point togh auth setup-git. Because it would explain better how credentials are stored, because they are stored using a credential manager. And also (but this is more another issue)gh auth setup-gitdoesn't explain what it is setting up:This command configures git to use GitHub CLI as a credential helper. For more information on git credential helpers please reference: https://git-scm.com/docs/gitcredentials.
I think it should explain what it is changing in
.gitconfig. For example will it automatically configure your email and username with your github's account details? (see #4351 (comment)) I don't think so, but it doesn't explain it anywhere.Reacted by Marko Milos and Josh SorefI wonder if there is an way to ask gh to report credentials (token) for a specific server. I am writing a python tool that uses github api to perform some tasks and re-using authentication from gh makes it easier for users instead of adding another place to store credentials.
- Reacted by Marco Valente and thienantran010
I think
ghrespects several environment variables so that the exact location varies: https://cli.github.com/manual/gh_help_environmentSo, I guess mentioning the possibility of storing credentials inside the config dir on the document above would be helpful.
where does
gh auth tokenget its token? none of these files contain the key:]$ strace -f gh auth token 2>&1 | grep open openat(AT_FDCWD, "/sys/kernel/mm/transparent_hugepage/hpage_pmd_size", O_RDONLY) = 3 [pid 2175448] openat(AT_FDCWD, "/usr/bin/gh", O_RDONLY|O_CLOEXEC) = 3 [pid 2175448] openat(AT_FDCWD, "/etc/localtime", O_RDONLY) = 3 [pid 2175448] openat(AT_FDCWD, "/home/user/.config/gh/config.yml", O_RDONLY|O_CLOEXEC) = 3 [pid 2175448] openat(AT_FDCWD, "/home/user/.config/gh/hosts.yml", O_RDONLY|O_CLOEXEC) = 3
Tokens are stored in the keychain as of #449
So tokens are not stored as plain text in a config file, but running
gh auth tokenwill still display it?Assuming e. g. some package manager's install script wants to collection system information, the keychain-based storage does not help, right? Or is the token being displayed a short-lived one?
Describe the feature or problem you’d like to solve
I can't find any information on the website or in the CLI help command about where authentication information is stored.
Proposed solution
Document where GH CLI stores authentication credentials. Also explain the relationship of this with existing GitHub credentials you may have on your system, like an SSH key or git https credentials in the keychain.
This helps the user understand the security and practical implications of logging in to the CLI.