Repository navigation
Credential-based login is broken after removal of /session endpoint #380
Description
Activity
I'm experiencing this as well. Our GitLab CE was just updated to 10.2.1 this last weekend and now gl.auth throws a 404. I'm using the latest version of python-gitlab.
Without the
/sessionendpoint python-gitlab cannot do password authentication.One possible solution is to use cookie authentication:
- use python-requests to authenticate on the web UI (POST on
/users/sign_in) - get the cookie from the answer
- create a
requests.Sessionobject and setup the cookies - use the session object to create a Gitlab connexion
- create/get a token from the API
- create a new gitlab object with token authentication
I have not tested this solution but according to Gitlab docs cookie authentication is supposed to work.
- use python-requests to authenticate on the web UI (POST on
Experiencing this too as soon as upgraded to 10.2
I am experiencing the same problem even I didn't upgrade gitlab. It seems the commands:
s = gitlab.Gitlab('https://gitlab.com',email='my_username',password='my_password')
s.auth()not working.
Thank you for the response!
im experiencing the same issue with our updated Gitlab instance to 10.2
GitLab has decided to remove the
/sessionendpoint so there is nothing much I can do.I've successfully used cookie authentication on gitlab.com with the following code: https://gist.github.com/gpocentek/bd4c3fbf8a6ce226ebddc4aad6b46c0a
I'll add some documentation to python-gitlab.
Reacted by ahsobhi and OortJacek@gpocentek , do you mean that there will be only token authentication since GL10.2?
found in GL changelog 10.2
Remove Session API now that private tokens are removed from user API endpoints.@gpocentek Do you plan on integrating this workaround into python-gitlab?
@GhostLyrics I'm afraid not, because there are multiple ways to authenticate using the web UI (LDAP and DB authentication use different endpoints for instance), and I'm not really sure that things will not change and break.
GitLab devs clearly want to make personal token authentication the default. This makes full automation more complicated (functional testing for python-gitlab needs to be updated as well), but it also makes sense.
My plan to resolve this issue is to update the documentation with code examples, to make initial setup of tokens easier.
@gpocentek Thank you for your efforts and the code sample, it works like a charm, now i do agree with you that things might change and break, GitLab undergoes major changes every few months, adding new features and functionality, we've been using it since it was v4 and it has come a long long way
@gpocentek - Thanks for the update Gauvain. I see now that it's just a change in GitLab's code, and nothing you can do about it. The module is great though, and I appreciate your work. I've converted to using a private token, which I programmatically pull from a password management system using my credentials. For others, if you don't have a secure password system, you can use a token of an account with less privileges on your GitLab projects, and generate a token for that account to pull code. It's not perfect, but it's an option.
Hi! We've also hit this problem in git-as-svn/git-as-svn#154. Did anyone try to file a bugreport to GitLab so they would consider returning back password-based authentication API? I'm also interested in GitLab ticket that triggered removal of /session API.
Okay, it is possible to perform login/password -> token authentication even with GitLab 10.2: https://docs.gitlab.com/ce/api/oauth2.html#resource-owner-password-credentials
That's how it was done in git-as-svn (Java): slonopotamus/git-as-svn@8a4d067
So I think you should reopen this issue and reimplement login/password authentication via OAuth2 too.
- locked as resolved and limited conversation to collaborators
on Nov 9, 2021
/api/v4/sessionhas been removed and it is currently not possible to log in via email/password combination. [Deprecation notice, Changelog]I use this to completely automate testing (e.g. create a GitLab instance, set a password for root, run some tests, tear everything down).