Lesson 17 / الدرس 17
Authentication: proving it is you / المصادقة: إثبات أنك أنت
GitHub will not take your password on the command line, and that surprises people. There are two accepted ways to prove who you are, and one of them you already set up in the terminal course.
لن يقبل GitHub كلمة مرورك في سطر الأوامر، وهذا يفاجئ الناس. وثمة طريقتان مقبولتان لإثبات من أنت، وإحداهما جهّزتها بالفعل في دورة الطرفية.
Reading a public repository needs nothing. Writing to one — git push — has to prove you are allowed to, and GitHub stopped accepting account passwords for this years ago. The two ways that work are an SSH key and a personal access token.
git push — فعليها أن تثبت أن ذلك مسموح لك، وقد كفّ GitHub عن قبول كلمات مرور الحسابات لهذا منذ سنوات. والطريقتان اللتان تعملان هما مفتاح SSH ورمز وصول شخصي.SSH keys — the same ones as before
ls ~/.ssh do you already have a pair?
ssh-keygen -t ed25519 -C "you@example.com" make one if not
cat ~/.ssh/id_ed25519.pub the PUBLIC one — copy this
... paste it into GitHub: Settings -> SSH and GPG keys -> New SSH key ...
ssh -T git@github.com test it
Hi ahmed! You've successfully authenticated.
Tokens, and which to choose
The other route is a personal access token — a long generated string that you use in place of a password. GitHub creates it under Settings, you choose what it is allowed to do and when it expires, and you see it exactly once. It is the right choice on a machine where you cannot install an SSH key, and it is what a script or a deployment uses.
| SSH key | Token | |
|---|---|---|
| Set up once per | Machine | Machine, and it expires |
| Remote address looks like | git@github.com:you/site.git | https://github.com/you/site.git |
| Typed in daily | No | No, if stored — see below |
| Can be limited to one repository | Awkwardly | Yes |
| Best for | Your own machine | Servers, scripts, temporary access |
For your own laptop, use an SSH key. The address in the first column is the one you will choose in the next lesson, and it is how git knows which method to use — the protocol is in the URL.
.git/config نصًا عاديًا، حيث يجده أول من ينظر في ذلك الجهاز. وأعطِ كل رمز تاريخ انتهاء وأضيق الصلاحيات التي تعمل.
If you do use tokens, let a credential helper store it so you type it once: git config --global credential.helper osxkeychain on macOS, or store elsewhere — though store means a plain file, so prefer the system keychain where there is one. On a shared or borrowed machine, use neither and let it ask every time.
git config --global credential.helper osxkeychain على macOS، أو store في غيرها — وإن كان store يعني ملفًا عاديًا، ففضّل سلسلة مفاتيح النظام حيث توجد. وعلى جهاز مشترك أو مستعار، لا تستخدم أيًّا منهما ودعه يسأل في كل مرة.Try it live / جرّب بنفسك
Check yourself / اختبر نفسك
1. Which file do you paste into GitHub?
The .pub one. If what you copied begins with -----BEGIN OPENSSH PRIVATE KEY-----, it is the wrong file.
.pub. فإن كان ما نسخته يبدأ بـ-----BEGIN OPENSSH PRIVATE KEY-----، فهو الملف الخطأ.
2.
Why will GitHub not accept your account password for git push?
git push؟A key or token can be limited and revoked on its own, without changing the password that protects your whole account.
3. Why should a token never go into a remote URL?
Anyone who can read that file has your token, and it carries your account's permissions. A credential helper stores it properly instead.
Score / النتيجة: 0 / 3
Your task / مهمتك
Set up authentication with GitHub and prove it works. Show ls -l ~/.ssh with the permissions, the first few characters of your public key only, and the output of ssh -T git@github.com. Then explain in your own words why GitHub asks for a key rather than your password, and what you would do differently on a machine you did not own.
جهّز المصادقة مع GitHub وأثبت أنها تعمل. أظهر ls -l ~/.ssh بالصلاحيات، وأول محارف مفتاحك العام فقط، ومخرَج ssh -T git@github.com. ثم اشرح بكلماتك لماذا يطلب GitHub مفتاحًا لا كلمة مرورك، وما الذي ستفعله بشكل مختلف على جهاز لا تملكه.
- ls -l ~/.ssh showing the private key at 600 ls -l ~/.ssh يُظهر المفتاح الخاص بصلاحية 600
- A successful ssh -T git@github.com ssh -T git@github.com ناجح
- Only public key content anywhere in the page لا محتوى إلا من المفتاح العام في الصفحة
- What you would do on a machine you do not own ما ستفعله على جهاز لا تملكه