Is there a way in Visual Studio Code to set an git/SSH command *only* for use with background fetches?

Viewed 44

Here's the context for this:

VS Code on Mac v 1.68.1, installed via Homebrew, macOS 12.4, remote end is FreeBSD 12.3 (which includes openSSH 7.9)

I have background git fetching turned on. When I log in, it's either with GSSAPI Authentication (which requires that I kinit first) OR with a password, which we allow on our VPN (i.e. the world cannot brute force us).

So, from a shell, I can type "git pull" and be fine, I'll get prompted for a password if I don't have an active Kerberos ticket. But git background fetches cause sshd/ssh to prompt for a password, that cannot be displayed to me.

This feels like a bug, and it feels like anything "background" should basically set -o PasswordAuthentication=No (and similar, like -o ChallengeResponseAuthentication) to ssh.

This trips up our IDS as it looks like someone is trying to brute force my login.

Here are the ways forward I see:

  • Just turning off background fetching for this repo, if that's even possible. (It seems I have this turned on at the "User" level, which overrides anything else.)

  • Allowing the background fetch to Specify its own ssh command (this option doesn't exist yet)

  • Similarly, allowing background fetch to set its own environment variables.

  • Using some kind of global ssh wrapper that sees how the command is being called. (Feels Hacky)

  • Giving background-fetch some kind of test to see if auth is likely to succeed (in my case this would be running klist).

  • Setting some kind of per-repo ssh command override (i.e. in a .git/config) that basically turns off any kind of interactive authentication. (Again, I like being able to use my password when it's presented as an option, so killing it globally is not a preference).

If the answer here is "I should open a feature request with VS Code, then so be it" but there may be some deep git or VS Code magic I haven't discovered for exactly this.

1 Answers

Regarding HTTPS, check forst if git config --global credential.manager is set: it should be able to cache your credentials, allowing you to not enter a password every time.

For SSH, check if your private key is passphrase protected: you would have to deal with ssh-agent if it is.

And see if git config --global url.git@github.com:.insteadOf https://github.com/ would help Git consider SSH URL even if HTTPS ones are used.
Replace github.com by the remote domain you are using.

Related