GitHub认证问题:拉取推送需重复验证,能否通过Git配置全局解决?
当前问题
克隆组织仓库时,执行git clone https://github.com/[organization]/[repo].git,输入用户名+个人访问令牌能成功克隆,但执行pull/push时CLI反复要求输入凭据;使用Fork工具拉取时出现以下错误:
/usr/local/share/gcm-core/git-credential-manager-core get: /usr/local/share/gcm-core/git-credential-manager-core: No such file or directory
/usr/local/share/gcm-core/git-credential-manager-core erase: /usr/local/share/gcm-core/git-credential-manager-core: No such file or directory
remote: Support for password authentication was removed on August 13, 2021.
remote: Please see https://docs.github.com/en/get-started/getting-started-with-git/about-remote-repositories#cloning-with-https-urls for information on currently recommended modes of authentication.
fatal: Authentication failed for 'https://github.com/accurat/edf-methanesat.git/'In a case you entered incorrect password, please
update it in Keychain Access application.
当前临时解决方式是为每个新克隆仓库执行:
git remote set-url origin https://[token]@github.com/[organization]/[repo].git
问题解答
1. 临时解决方式是否正确?
这个方法可行,但存在明显弊端:
- 个人访问令牌会明文存储在仓库的
.git/config文件中,若该文件被意外分享或泄露,令牌可能被滥用; - 需要为每个仓库单独配置,操作繁琐。
2. 全局配置解决方案
推荐两种更高效、安全的全局处理方式:
方式一:使用Git Credential Manager(推荐)
报错提示找不到git-credential-manager-core,说明你未安装官方推荐的凭据管理工具。它能安全存储令牌到系统密钥链(如Mac的Keychain Access),自动复用凭据,无需重复输入:
- 安装Git Credential Manager(GCM);
- 执行全局配置命令:
git config --global credential.helper manager-core - 第一次执行GitHub仓库操作(如
pull/push)时,输入用户名和个人访问令牌,GCM会自动将凭据存入系统密钥链,后续操作无需再手动输入。
方式二:全局配置GitHub凭据
若不想安装GCM,可直接在Git全局配置中设置GitHub的用户名和令牌,所有GitHub仓库将自动使用该凭据:
git config --global user.name "你的GitHub用户名" git config --global credential.https://github.com.username "你的GitHub用户名" git config --global credential.https://github.com.password "你的个人访问令牌"
注意:这种方式令牌会明文存储在全局Git配置文件中,安全性低于GCM,仅作为备选方案。
额外提示
如果Mac的Keychain Access中存在旧的GitHub凭据,可能导致认证冲突,建议删除相关旧条目后再配置新凭据。
内容的提问来源于stack exchange,提问作者marielle

