Mercurial HTTPS push continues after server password change without cache clear
0 reputation · 02 Mar 2021, 23:01 UTC
Determine whether Mercurial automatically invalidates cached HTTPS credentials when the server‑side password is changed, or if manual cache clearing or process restart is required for the change to take effect.
Mercurial stores HTTPS credentials in the operating system keyring or .hgrc and does not query the store for expiration until the cache entry is explicitly cleared or the Mercurial process restarts, leaving a window where outdated credentials may still be used.
Does Mercurial offer a setting to disable credential caching for HTTPS? Is there a way to force Mercurial to re‑query the keyring before each operation? Should administrators rely on external key‑rotation policies to enforce credential expiration?