Lesson 17 / الدرس 17

Authentication: proving it is you / المصادقة: إثبات أنك أنت

GitHub will not take your password on the command line, and that surprises people. There are two accepted ways to prove who you are, and one of them you already set up in the terminal course.

لن يقبل GitHub كلمة مرورك في سطر الأوامر، وهذا يفاجئ الناس. وثمة طريقتان مقبولتان لإثبات من أنت، وإحداهما جهّزتها بالفعل في دورة الطرفية.

Reading a public repository needs nothing. Writing to one — git push — has to prove you are allowed to, and GitHub stopped accepting account passwords for this years ago. The two ways that work are an SSH key and a personal access token.

SSH keys — the same ones as before

ls ~/.ssh                          do you already have a pair?
ssh-keygen -t ed25519 -C "you@example.com"   make one if not
cat ~/.ssh/id_ed25519.pub          the PUBLIC one — copy this

   ... paste it into GitHub: Settings -> SSH and GPG keys -> New SSH key ...

ssh -T git@github.com              test it
Hi ahmed! You've successfully authenticated.
This is lesson 21 of the terminal course, applied. If you did that lesson you already have the pair and only need to paste the public half into GitHub. Run the demonstration for which file goes where — the one thing that must not be got wrong.

Tokens, and which to choose

The other route is a personal access token — a long generated string that you use in place of a password. GitHub creates it under Settings, you choose what it is allowed to do and when it expires, and you see it exactly once. It is the right choice on a machine where you cannot install an SSH key, and it is what a script or a deployment uses.

SSH keyToken
Set up once perMachineMachine, and it expires
Remote address looks likegit@github.com:you/site.githttps://github.com/you/site.git
Typed in dailyNoNo, if stored — see below
Can be limited to one repositoryAwkwardlyYes
Best forYour own machineServers, scripts, temporary access

For your own laptop, use an SSH key. The address in the first column is the one you will choose in the next lesson, and it is how git knows which method to use — the protocol is in the URL.

If you do use tokens, let a credential helper store it so you type it once: git config --global credential.helper osxkeychain on macOS, or store elsewhere — though store means a plain file, so prefer the system keychain where there is one. On a shared or borrowed machine, use neither and let it ask every time.

Try it live / جرّب بنفسك

Preview / المعاينة

Check yourself / اختبر نفسك

1. Which file do you paste into GitHub?

2. Why will GitHub not accept your account password for git push?

3. Why should a token never go into a remote URL?

Your task / مهمتك

Set up authentication with GitHub and prove it works. Show ls -l ~/.ssh with the permissions, the first few characters of your public key only, and the output of ssh -T git@github.com. Then explain in your own words why GitHub asks for a key rather than your password, and what you would do differently on a machine you did not own.

جهّز المصادقة مع GitHub وأثبت أنها تعمل. أظهر ls -l ~/.ssh بالصلاحيات، وأول محارف مفتاحك العام فقط، ومخرَج ssh -T git@github.com. ثم اشرح بكلماتك لماذا يطلب GitHub مفتاحًا لا كلمة مرورك، وما الذي ستفعله بشكل مختلف على جهاز لا تملكه.

  • ls -l ~/.ssh showing the private key at 600 ls -l ~/.ssh يُظهر المفتاح الخاص بصلاحية 600
  • A successful ssh -T git@github.com ssh -T git@github.com ناجح
  • Only public key content anywhere in the page لا محتوى إلا من المفتاح العام في الصفحة
  • What you would do on a machine you do not own ما ستفعله على جهاز لا تملكه
How do you want to submit? / كيف تريد التسليم؟