#995692 svn client does not allow plain text password store

Package:
subversion
Source:
subversion
Description:
Advanced version control system
Submitter:
Date:
2022-07-12 14:39:11 UTC
Severity:
normal
Tags:
#995692#5
Date:
2021-10-04 09:12:00 UTC
From:
To:
I've installed subversion in a chroot from unstable. It suddenly refused to remember my password. There was no clear indication for why. After editing all config files I could think of it still silently refused to remember my password.

It turns out this feature needs to be enabled in ./configure using --enable-plaintext-password-storage

I am a long tiem svn user. I have situations where storing password in plain text is okay from security viewpoint (e.g. encrypted file system). Enabling this in configure will not force users to store passwords in plain; the svn client even warns and asks the user about this when it is about to happen.

Please enable this feature so my workflow will not break after an upgrade.

#995692#10
Date:
2022-07-04 12:08:15 UTC
From:
To:
Dear packager!

This is biting me more and more often. It's real annoying that I have to
compile from source with such extensive dependencies because of this one
missing configure setting. For me, severity of this bug is becoming major.

#995692#15
Date:
2022-07-09 01:40:45 UTC
From:
To:
Thanks for your patience.  I intended to follow up on this, but then it
fell off my radar.  I'll get back to this in the next few days.

Cheers,

#995692#18
Date:
2022-07-11 12:09:04 UTC
From:
To:
Hello,

Bug #995692 in subversion reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/jamessan/subversion/-/commit/48c9a8ca6cca5a66170294f953c20c82ba0e1f63
------------------------------------------------------------------------
Re-enable the ability to store plaintext passwords

There are valid use cases where having to use a non-plaintext store is
not practical, so outright disabling the functionality does more harm
than good.

Re-enabling this capability does not make it the default, rather just
provides functionality that had existed for decades prior.

Upstream has also discussed this[0] and are looking into[1] re-enabling
the functionality along with some additional UX to help manage the
credentials.

[0]: https://lists.apache.org/thread/b6g2hx2m3s117wcmno08opl874ons3q8
[1]: https://lists.apache.org/thread/shzxh04l493qnj8pdt8vl0x4gkjrkvcy

Closes: #995692
Signed-off-by: James McCoy <jamessan@debian.org>
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/995692

#995692#25
Date:
2022-07-12 14:37:46 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
subversion, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 995692@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
James McCoy <jamessan@debian.org> (supplier of updated subversion package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 12 Jul 2022 10:03:54 -0400
Source: subversion
Architecture: source
Version: 1.14.2-3
Distribution: unstable
Urgency: medium
Maintainer: James McCoy <jamessan@debian.org>
Changed-By: James McCoy <jamessan@debian.org>
Closes: 995692
Changes:
 subversion (1.14.2-3) unstable; urgency=medium
 .
   * Re-enable the ability to store plaintext passwords (Closes: #995692)
   * Bump debhelper-compat to 13
   * Adjust lacks-unversioned-link-to-shared-library overrides
   * Adjust package-contains-upstream-installation-documentation override
   * Document uninstalled files in debian/not-installed
Checksums-Sha1:
 8e12aabe72ce7e48dfb44dc9e71c030379faf93e 4046 subversion_1.14.2-3.dsc
 cb5f1047a515cb1e12abdb5938492f254c28fda7 336384 subversion_1.14.2-3.debian.tar.xz
Checksums-Sha256:
 09b88f161ce31aa691728d2decf9a78a16078da0812eeb68f93d9af0dd74431d 4046 subversion_1.14.2-3.dsc
 bab721201e0673a74b64263ae9dd460b1193d71f905c2cc76c7a21f0d6e7acc0 336384 subversion_1.14.2-3.debian.tar.xz
Files:
 b24fdbc268c753b64d08119872af910e 4046 vcs optional subversion_1.14.2-3.dsc
 1f4799c5083934656578168e0151de05 336384 vcs optional subversion_1.14.2-3.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQKoBAEBCgCSFiEEkb+/TWlWvV33ty0j3+aRrjMbo9sFAmLNf7RfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDkx
QkZCRjRENjk1NkJENURGN0I3MkQyM0RGRTY5MUFFMzMxQkEzREIUHGphbWVzc2Fu
QGRlYmlhbi5vcmcACgkQ3+aRrjMbo9tM/g/+Km6HdQ9QOVQvPd3K2HDCrY5yuz45
mgA5UiU8KIh1kPDbHZs/SraMqn/P5C4qyS8/Kl8OKVZmPqDZzTPQb4IX2PzuP7Gb
CWNi4aDMccLa8DAedsJQi6TI5WfF6UU8wReoJHa+mhaoF+PwkIN+OaVCkaB6AB0h
7oRSiHy3MS8EgdE1wuPpxYiVKPKmIxzaGxVmklCfnKch9oz5vel9hISyZ4JKtQV2
nJV/gcN5/GTIK6xHv8+2zxQUuiC8VwdzlwNB+V4uiXmunAj04Tt2KJXuLNFwi9k7
TE/fcjTiH45HWAVACzObTwnFeZ0tFO0F/GivAGHwy51VkkRY7JUnW0ub6kQCF121
jtdAvyiUddlETMUUzXsOG8o01EfgeAZ2j3/wpRK9gU1XlX5lqgFCM6/zYv9sU1Kc
ZPGO7STfOIAtvNAXKGjZAtlpdE3Hjeia4xlS8Hp0ZTQs1sEAU/hoKgtvcfKIiDK6
lAwZIBCcQRoT0Mcq9O0re28ZAoVHunneSv6V1u/T/xb8nCo8ro17y3QBKxMM4++S
fSK8/wAhedmC6BxFo6BmTMHNozrLsdoZREs0yZuVqUnel8sZhGPAh7d1vR71Nhfj
wVTC8llcFowE34jggAUO/2bGUtN8g8EB1wVPWPGVU8hDIndw+j4YFwRRNuLHANq6
n0EzI6Y5UUKe05E=
=/ko+
-----END PGP SIGNATURE-----