Does TortoiseGit cache failed credential attempts to avoid repeated prompts?
0 reputation · 09 Sept 2020, 08:17 UTC
Goal: Assess whether TortoiseGit should introduce a mechanism to cache failed credential attempts in order to reduce repeated authentication prompts when stored credentials have expired.
Constraints: TortoiseGit delegates credential handling to the underlying Git credential helper (e.g., Git Credential Manager for Windows or wincred) and currently treats each expired credential as a fresh request without any back‑off or caching. The behavior may vary depending on the helper in use, and any caching must not undermine the least‑privilege principle or introduce security risks such as replay of failed attempts.
Questions: Should TortoiseGit cache failed credential attempts for a limited period? What timeout or retry strategy would balance usability with security? How would such caching interact with different credential helpers without requiring helper‑specific changes?