Skip to content

Add support for .netrc #288

Description

@travi

Describe the feature or problem you’d like to solve

A clear and concise description of what the feature or problem is.

probably more of a question than request to start with since i haven't yet had a chance to check out many details yet, but thought it would get this question on the list early.

since curl can use credentials, including tokens, configured in a ~/.netrc file, i have the github api already configured there. also, git uses curl under the hood, so credentials there can be used through git as well.

if credentials exist there, can they be used for gh as well?

Proposed solution

How will it benefit CLI and its users?

those that already have credentials configured for curl or git using a ~/.netrc could avoid configuring auth again for gh

Activity

  1. changed the title [-].netrc support[/-] [+]Add support for .netrc[/+] on Jan 31, 2020
  2. narqo commented on Feb 3, 2020

    @narqo

    Can this be extended to "Support for secure credential storage"?

    Storing an OAuth token in a plain-text file feels like a potential security issue for a user. That might be an issue for the official GitHub client, as the expectations about the security for an average user are higher than from a "random tool on the internet". I propose starting the discussion on the integration of the OS's credential storages (keychain on macOS, for example).

    docker/docker-credential-helpers can be looked at as the starting point.

  3. tierninho commented on Feb 4, 2020

    @tierninho
    Contributor

    Adding this comment from another thread addressing this request:

    We don't yet respect the netrc file, but we appreciate the suggestion!

  4. narqo commented on Feb 4, 2020

    @narqo

    Apparently, but not surprisingly, there are on-going discussions on the topic in hub, where authors of cli were involved too mislav/hub#1217

  5. added
    coreThis issue is not accepting PRs from outside contributors
    authrelated to tokens, authentication state, or oauth
    on Oct 7, 2020
  6. tonglil commented on Jan 27, 2022

    @tonglil

    Storing an OAuth token in a plain-text file feels like a potential security issue for a user

    This is used by some CI systems to authenticate to GH.
    It might be potentially insecure, but it is still a valid way of using the GH API.

  7. adam-azarchs commented on Mar 9, 2022

    @adam-azarchs

    There are several cases, e.g. build systems which know how to pull dependencies over https, where being able to put the credentials in ~/.netrc would be very useful. It's not terribly secure, but it's no worse than ~/.git-credentials, which gh already knows how to update.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    authrelated to tokens, authentication state, or oauthcoreThis issue is not accepting PRs from outside contributorsenhancementa request to improve CLI

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions