From: "NARUSE, Yui" Date: 2010-11-25T22:26:38+09:00 Subject: [ruby-core:33380] Re: [Ruby 1.9-Feature#4071] support basic auth for Net::HTTP.get requests Hi, (2010/11/25 18:45), Marc-Andre Lafortune wrote: > The class URI::HTTP has two attributes named 'user' and 'password'. I > feel these can not be removed for compatibility reasons. Partly yes, I think userinfo in HTTP URI is in RFC3986. Different from mathew, I think RFC3986 syntactically allows userinfo in HTTP URI because of compatibility to existing implementations. > If you > disagree, please say so. Otherwise, we have to accept that the > information is there (even if you/some RFC think it's a bad idea). > > Note that setters exist too, so they can be specified in other ways > than with through the "user:pass@...": > u = URI("https://github.com") > u.user = "bob" > u.password = "foo" > > The Net::HTTP.get and Net::HTTP.post_form both accept a URI::HTTP > argument. I feel they should deal with all the information provided by > the URI::HTTP class. No to "they should deal with all the information provided by the URI::HTTP class". > This includes 'user' and 'password'. Currently, `get` doesn't, but > `post_form` does. I feel that changing `get` would make the situation > consistent, convenient and shouldn't impact compatibility. Don't change `get` is from "correctness". > I feel that discouraging the use of user& password, or of basic > authentifcation over HTTP is not the role of the standard library. I think it *is* the role of the standard library. > What next, a warning when we set `request.basic_auth`? If it is needed. But I think it isn't needed because basic auth with SSL is enough secure. > Moreover, if it was deemed important that URI didn't have a user& > password, then `get` is the wrong level to intervene. > > I remark that a scheme set to 'https' is currently ignored by `get` > and `post_form`, which I believe to be erroneous, counter-intuitive > and insecure. Either I'm missing the ideology behind ignoring info > from URI, or it is simply a similar oversight as ignoring the user& > password. I believe it is related and in the right context, as > exemplified by the following line: > > Net::HTTP.get(URI("https://bob:qwery@github.com")) Why is it the right context? At least in github's context, it only includes the user name. > If `get` worked as I believe it should, the above line would work and > security would not be compromised (at least at the network level), > while currently the request is made in HTTP (on port 443) and no > credential is ever sent. RFC's argument is mainly for the client side. The network level is out of the scope. (and your point is true for basic auth it self) -- NARUSE, Yui