Is it possible to do not leak instantly repository access token when cloning repository?The suggested clone url is:git clone https://x-token-auth:${THE TOKEN LEAKS HERE EVERYWHERE AS PLAIN TEXT WHEN ONE WANT TO CLONE THE REPO}@bitbucket.org/my-workspace/repo.gitThis leaks completely everywhere, in console, CI configuration (the repo address)
Hi @Mikołaj and welcome to the community!
Even though it is possible to use a repository access token as part of the clone URL, this is something we do not recommend:
This method is useful if the Repository Access Token has been stored securely as a 'secret' variable in a build tool.
If this is not possible with the CI tool you are using, and if you only need to clone and pull from repos (and not push or any other operation), you can consider using SSH Access keys instead:
Access keys provide read-only access to a certain repository and are commonly used in CI tools that need to pull or clone a repository.
If you have any questions, please feel free to let me know.
Kind regards,Theodora
I was about to use the repository access token, to allow CI to push build status back to the Bitbucket. But since TeamCity requires username and token to do that (https://www.jetbrains.com/help/teamcity/commit-status-publisher.html#Bitbucket+Cloud), but username for access token is not available, then I simply abandon this idea.So in this case, for read-only access, I'll check the ssh access key.
Hi Mikołaj,
Thank you for the update.
If you would like to allow CI to push back to the repository, you could use the username and an app password of an account that has write access to this repo. You can read more app passwords here:
Unfortunately, app password is bound to the specific user, which should be avoided because CI server is not about users but about projects. What's more, users may change frequently.
The ideal option would be to have an access-key with additional write permissions - like access tokens.
It looks like you're new here. Sign in or register to get started.