2 * A git credential helper that interface with Windows' Credential Manager
12 #define ARRAY_SIZE(x) (sizeof(x)/sizeof(x[0]))
14 static void die(const char *err
, ...)
18 va_start(params
, err
);
19 vsnprintf(msg
, sizeof(msg
), err
, params
);
20 fprintf(stderr
, "%s\n", msg
);
25 static void *xmalloc(size_t size
)
27 void *ret
= malloc(size
);
35 /* MinGW doesn't have wincred.h, so we need to define stuff */
37 typedef struct _CREDENTIAL_ATTRIBUTEW
{
42 } CREDENTIAL_ATTRIBUTEW
, *PCREDENTIAL_ATTRIBUTEW
;
44 typedef struct _CREDENTIALW
{
50 DWORD CredentialBlobSize
;
51 LPBYTE CredentialBlob
;
54 PCREDENTIAL_ATTRIBUTEW Attributes
;
57 } CREDENTIALW
, *PCREDENTIALW
;
59 #define CRED_TYPE_GENERIC 1
60 #define CRED_PERSIST_LOCAL_MACHINE 2
61 #define CRED_MAX_ATTRIBUTES 64
63 typedef BOOL (WINAPI
*CredWriteWT
)(PCREDENTIALW
, DWORD
);
64 typedef BOOL (WINAPI
*CredEnumerateWT
)(LPCWSTR
, DWORD
, DWORD
*,
66 typedef VOID (WINAPI
*CredFreeT
)(PVOID
);
67 typedef BOOL (WINAPI
*CredDeleteWT
)(LPCWSTR
, DWORD
, DWORD
);
69 static HMODULE advapi
;
70 static CredWriteWT CredWriteW
;
71 static CredEnumerateWT CredEnumerateW
;
72 static CredFreeT CredFree
;
73 static CredDeleteWT CredDeleteW
;
75 static void load_cred_funcs(void)
78 advapi
= LoadLibrary("advapi32.dll");
80 die("failed to load advapi32.dll");
82 /* get function pointers */
83 CredWriteW
= (CredWriteWT
)GetProcAddress(advapi
, "CredWriteW");
84 CredEnumerateW
= (CredEnumerateWT
)GetProcAddress(advapi
,
86 CredFree
= (CredFreeT
)GetProcAddress(advapi
, "CredFree");
87 CredDeleteW
= (CredDeleteWT
)GetProcAddress(advapi
, "CredDeleteW");
88 if (!CredWriteW
|| !CredEnumerateW
|| !CredFree
|| !CredDeleteW
)
89 die("failed to load functions");
92 static WCHAR
*wusername
, *password
, *protocol
, *host
, *path
, target
[1024];
94 static void write_item(const char *what
, LPCWSTR wbuf
, int wlen
)
97 int len
= WideCharToMultiByte(CP_UTF8
, 0, wbuf
, wlen
, NULL
, 0, NULL
,
101 if (!WideCharToMultiByte(CP_UTF8
, 0, wbuf
, wlen
, buf
, len
, NULL
, FALSE
))
102 die("WideCharToMultiByte failed!");
105 fwrite(buf
, 1, len
, stdout
);
111 * Match an (optional) expected string and a delimiter in the target string,
112 * consuming the matched text by updating the target pointer.
115 static LPCWSTR
wcsstr_last(LPCWSTR str
, LPCWSTR find
)
117 LPCWSTR res
= NULL
, pos
;
118 for (pos
= wcsstr(str
, find
); pos
; pos
= wcsstr(pos
+ 1, find
))
123 static int match_part_with_last(LPCWSTR
*ptarget
, LPCWSTR want
, LPCWSTR delim
, int last
)
125 LPCWSTR delim_pos
, start
= *ptarget
;
128 /* find start of delimiter (or end-of-string if delim is empty) */
130 delim_pos
= last
? wcsstr_last(start
, delim
) : wcsstr(start
, delim
);
132 delim_pos
= start
+ wcslen(start
);
135 * match text up to delimiter, or end of string (e.g. the '/' after
136 * host is optional if not followed by a path)
139 len
= delim_pos
- start
;
143 /* update ptarget if we either found a delimiter or need a match */
144 if (delim_pos
|| want
)
145 *ptarget
= delim_pos
? delim_pos
+ wcslen(delim
) : start
+ len
;
147 return !want
|| (!wcsncmp(want
, start
, len
) && !want
[len
]);
150 static int match_part(LPCWSTR
*ptarget
, LPCWSTR want
, LPCWSTR delim
)
152 return match_part_with_last(ptarget
, want
, delim
, 0);
155 static int match_part_last(LPCWSTR
*ptarget
, LPCWSTR want
, LPCWSTR delim
)
157 return match_part_with_last(ptarget
, want
, delim
, 1);
160 static int match_cred(const CREDENTIALW
*cred
)
162 LPCWSTR target
= cred
->TargetName
;
163 if (wusername
&& wcscmp(wusername
, cred
->UserName
))
166 return match_part(&target
, L
"git", L
":") &&
167 match_part(&target
, protocol
, L
"://") &&
168 match_part_last(&target
, wusername
, L
"@") &&
169 match_part(&target
, host
, L
"/") &&
170 match_part(&target
, path
, L
"");
173 static void get_credential(void)
179 if (!CredEnumerateW(L
"git:*", 0, &num_creds
, &creds
))
182 /* search for the first credential that matches username */
183 for (i
= 0; i
< num_creds
; ++i
)
184 if (match_cred(creds
[i
])) {
185 write_item("username", creds
[i
]->UserName
,
186 wcslen(creds
[i
]->UserName
));
187 write_item("password",
188 (LPCWSTR
)creds
[i
]->CredentialBlob
,
189 creds
[i
]->CredentialBlobSize
/ sizeof(WCHAR
));
196 static void store_credential(void)
200 if (!wusername
|| !password
)
204 cred
.Type
= CRED_TYPE_GENERIC
;
205 cred
.TargetName
= target
;
206 cred
.Comment
= L
"saved by git-credential-wincred";
207 cred
.CredentialBlobSize
= (wcslen(password
)) * sizeof(WCHAR
);
208 cred
.CredentialBlob
= (LPVOID
)password
;
209 cred
.Persist
= CRED_PERSIST_LOCAL_MACHINE
;
210 cred
.AttributeCount
= 0;
211 cred
.Attributes
= NULL
;
212 cred
.TargetAlias
= NULL
;
213 cred
.UserName
= wusername
;
215 if (!CredWriteW(&cred
, 0))
216 die("CredWrite failed");
219 static void erase_credential(void)
225 if (!CredEnumerateW(L
"git:*", 0, &num_creds
, &creds
))
228 for (i
= 0; i
< num_creds
; ++i
) {
229 if (match_cred(creds
[i
]))
230 CredDeleteW(creds
[i
]->TargetName
, creds
[i
]->Type
, 0);
236 static WCHAR
*utf8_to_utf16_dup(const char *str
)
238 int wlen
= MultiByteToWideChar(CP_UTF8
, 0, str
, -1, NULL
, 0);
239 WCHAR
*wstr
= xmalloc(sizeof(WCHAR
) * wlen
);
240 MultiByteToWideChar(CP_UTF8
, 0, str
, -1, wstr
, wlen
);
244 static void read_credential(void)
248 while (fgets(buf
, sizeof(buf
), stdin
)) {
250 int len
= strlen(buf
);
251 /* strip trailing CR / LF */
252 while (len
&& strchr("\r\n", buf
[len
- 1]))
258 v
= strchr(buf
, '=');
260 die("bad input: %s", buf
);
263 if (!strcmp(buf
, "protocol"))
264 protocol
= utf8_to_utf16_dup(v
);
265 else if (!strcmp(buf
, "host"))
266 host
= utf8_to_utf16_dup(v
);
267 else if (!strcmp(buf
, "path"))
268 path
= utf8_to_utf16_dup(v
);
269 else if (!strcmp(buf
, "username")) {
270 wusername
= utf8_to_utf16_dup(v
);
271 } else if (!strcmp(buf
, "password"))
272 password
= utf8_to_utf16_dup(v
);
274 die("unrecognized input");
278 int main(int argc
, char *argv
[])
281 "usage: git credential-wincred <get|store|erase>\n";
286 /* git use binary pipes to avoid CRLF-issues */
287 _setmode(_fileno(stdin
), _O_BINARY
);
288 _setmode(_fileno(stdout
), _O_BINARY
);
294 if (!protocol
|| !(host
|| path
))
297 /* prepare 'target', the unique key for the credential */
298 wcscpy(target
, L
"git:");
299 wcsncat(target
, protocol
, ARRAY_SIZE(target
));
300 wcsncat(target
, L
"://", ARRAY_SIZE(target
));
302 wcsncat(target
, wusername
, ARRAY_SIZE(target
));
303 wcsncat(target
, L
"@", ARRAY_SIZE(target
));
306 wcsncat(target
, host
, ARRAY_SIZE(target
));
308 wcsncat(target
, L
"/", ARRAY_SIZE(target
));
309 wcsncat(target
, path
, ARRAY_SIZE(target
));
312 if (!strcmp(argv
[1], "get"))
314 else if (!strcmp(argv
[1], "store"))
316 else if (!strcmp(argv
[1], "erase"))
318 /* otherwise, ignore unknown action */