fix: remove non-portable askpass bridge; rely on native git credentials
All checks were successful
CI / test (push) Successful in 17s
All checks were successful
CI / test (push) Successful in 17s
The askpass bridge bound a Unix-domain socket to a vault filesystem path (net.createServer().listen(...sock)). That is invalid on Windows, where Node's listen() expects a named pipe, so publish aborted with 'listen EACCES: permission denied ...askpass.sock' before git ever ran — even when the user's git could authenticate. The bridge was non-portable in general (Windows named pipes; the helper script needs a node binary on PATH). Remove the bridge and let the user's system git handle credentials via its native helpers (Git Credential Manager / osxkeychain / libsecret) for https and ssh-agent for ssh — the 'store nothing' model we already chose. GIT_TERMINAL_PROMPT=0 stays so git fails fast instead of hanging, and publish errors now include a credential/identity hint. Deletes askpass.ts and its test (3 tests); suite 32/32, tsc clean, build OK. Co-Authored-By: Claude
This commit is contained in:
@@ -42,11 +42,12 @@ An Obsidian plugin that publishes the active note as a Jekyll blog post via git.
|
||||
|
||||
## Credentials model
|
||||
|
||||
The plugin uses your **system git** binary for all remote operations. No passwords or tokens are stored inside Obsidian or the plugin's data files.
|
||||
The plugin uses your **system git** binary for all remote operations and stores **no** passwords or tokens inside Obsidian or the plugin's data files. Authentication is delegated entirely to git's own credential handling, which works across platforms:
|
||||
|
||||
When git needs a credential (e.g. HTTPS password or a personal access token), an **askpass bridge** intercepts the prompt and shows a native Obsidian modal so you can type the value. The value is passed directly to git through a temporary socket and is never persisted.
|
||||
- **HTTPS remotes** — git uses your configured credential helper: **Git Credential Manager** (bundled with Git for Windows), **osxkeychain** (macOS), or libsecret (Linux). The first push prompts you through that helper's own dialog and caches the result in your OS keychain. If no helper is configured, the publish fails fast with a clear message (the plugin sets `GIT_TERMINAL_PROMPT=0` so git never hangs waiting on a non-existent terminal).
|
||||
- **SSH remotes** — git uses your existing SSH agent / `~/.ssh` key configuration. Use an `ssh://` URL and make sure your key (or agent) is set up; no extra steps in the plugin.
|
||||
|
||||
For SSH remotes, the plugin relies on your existing SSH agent or `~/.ssh` key configuration — no extra steps needed.
|
||||
Commits are authored with the **Author name/email** from the plugin settings if set; otherwise git uses your machine's git identity (`user.name` / `user.email`). If neither is configured, git will refuse to commit — set an author in settings or configure a global git identity.
|
||||
|
||||
## Development
|
||||
|
||||
|
||||
Reference in New Issue
Block a user