From: James Edward Gray II Date: 2010-09-27T11:07:11+09:00 Subject: [ruby-core:32581] Re: [Ruby-Feature#3848][Open] Using http basic authentication for FTP with Open URI On Sep 26, 2010, at 9:01 PM, mathew wrote: > On Sun, Sep 26, 2010 at 20:57, James Edward Gray II > wrote: >> On Sep 26, 2010, at 8:44 PM, mathew wrote: >>> So building systems which store and process username and password in >>> this way is a bad idea. >> >> I'm not sure that really applies to open-uri's usage of this strategy. It's just >> a familiar interface, not some attempt to correctly mirror how FTP servers >> manage logins. Does that make sense? > > I agree that open-uri shouldn't care what is passed to it, and should > just pass the URI to URI for resolution. > > I'm not sure URI should be supporting username and password for http, > given the history, but there's also an argument for making the code > general and being permissive. > > I was mostly pointing out to the person who wanted to user user:pass > in URIs that he really shouldn't, even if Ruby lets him. OK, but, especially in the case of FTP, they aren't really. They are building a URL, just because that's open-uri's supported interface. Under the hood it picks this apart and does a proper FTP login. So this is just smoke and mirrors and not really any different than doing a normal FTP login. Do you see what I mean? James Edward Gray II