(GCMC - windows) git credential manager core keeps prompting for password (gitlab repo)

Viewed 1500

Following a change of my gitlab account password I'm running into troubles to set my credential helper. I uninstalled my previous git for windows version and installed the latest one including Git Credential Manager Core.

I'm using Android Studio and manage to fetch / pull / push through the IDE. Since I installed this new version of git for windows, a prompt is showing up every now and then. Worse, sometimes when I perfom a git operation my account gets blocked due to company policy (following multiple call with wrong password I guess).

I tried to set my credential helper to manager, manager-core but with no luck. I used to add entries into the windows authentication manager but they get removed from it, don't know by whom.

My remote repo is set with a https URL.

So my question is : how do I set GCMC to ask my password when my password has expired and cache the new one I'm givin ?

I've red a bit about GCMC but can't find the answer, this is crazy that new stuff are actually more complicated and buggy than older tools today deprecated (was working fine with wincred for example).

2 Answers

I ended up using an access token. I made a small doc (in French, sorry).

Contexte

Depuis la version v2.29.0, git for windows préconise l'utilisation de GCMC - Git Credential Manager Core - en remplacement de "Git Credential Manager" (deprecated) :

Important note: v2.29.0 and v2.29.1 upgrade existing users of Git Credential Manager for Windows (which was just deprecated) to Git Credential Manager Core ("GCM Core", which is the designated successor of the former). This is necessary because GitHub deprecated password-based authentication and intends to remove support for it soon, and GCM Core is prepared for this change."

Installation

  1. Dans les étapes d'installation de git for Windows, sélectionner Git Credential Manager Core

Configuration

  1. Une fois l'installation effectuée, ouvrir un bash git et valider que la commande git config credential.helper retourne bien manager-core
  2. Se rendre dans le gestionnaire d'identification Windows et supprimer les éventuelles entrées existantes vers git:https://git.xxxx
  3. Dans les settings gitlab, générer un access token (name : personal access token)
  4. Dans le répertoire d'un projet clôné depuis git, réaliser un git pull / fetch / push
  5. Une modale s'ouvre, renseigner alors en login : personal access token, password : le token nouvellement créé
  6. Valider l'ajout de la nouvelle entrée dans le gestionnaire d'identification Windows avec comme login personal access token
  7. Si votre IDE (testé avec IntelliJ / Android Studio) demande une authentification, cocher Use credential manager

Debug

En cas de problème et pour activer le debug ouvrir une invite de commande et taper :

setx GIT_TRACE %userprofile%\git.log
setx GCM_TRACE %userprofile%\git.log
setx GCM_TRACE_SECRETS 1 (attention, des informations sensibles seront visibles dans le log - access token -)

Après utilisation via git bash / IDE un fichier git.log devrait donc être présent dans votre répertoire %userprofile% (ce n'est pas instantané)

Extrait de log :

[RunAsync] Tracing of secrets is enabled. Trace output may contain sensitive information.
[RunInternalAsync] Git Credential Manager version X (Windows, .NET Framework X) 'store'
[ExecuteAsync] Start 'store' command...
[ExecuteAsync] Detecting host provider for input:
[ExecuteAsync]  protocol=https
[ExecuteAsync]  host=git.xxxx
[ExecuteAsync]  username=personal access token
[ExecuteAsync]  password=XXXXXXXXXXXXXXXXXXXXX  <-------- votre access token
[GetProvider] Performing auto-detection of host provider.
[ExecuteAsync] Host provider 'Generic' was selected.
[StoreCredentialAsync] Storing credential with service=https://git.xxxx account=personal access token...
[StoreCredentialAsync] Credential was successfully stored.
[ExecuteAsync] End 'store' command...

Pour désactiver le debug : supprimer les variables d'environnement GIT_TRACE, GCM_TRACE, GCM_TRACE_SECRETS

Apr. 2022: The latest GCM v2.0.692 does officially support GitLab GUI prompt.

See PR 621:

Add GUI prompts on all platforms for GitLab authentication. GUI prompts are required because if GCM/Git is invoked from an IDE without a terminal, there is no way for the user to authenticate for GitLab.

https://user-images.githubusercontent.com/5658207/156394932-8f40f33e-f4e4-4460-9380-54f46b82168a.png

Related