{"thread":{"id":"60990","subject":"[PATCH] send-email: implement SMTP bearer authentication","startedAt":"2024-02-25T10:34:54Z","lastAt":"2025-01-25T19:02:09Z","messageCount":7,"participants":["Julian Swagemakers","M Hickford","Shengyu Qu","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"489302","messageId":"20240225103413.9845-1-julian@swagemakers.org","threadId":"60990","inReplyTo":null,"subject":"[PATCH] send-email: implement SMTP bearer authentication","fromName":"Julian Swagemakers","fromEmail":"julian@swagemakers.org","sentAt":"2024-02-25T10:34:13Z","receivedAt":"2024-02-25T10:34:54Z","isPatch":true,"sender":{"key":"julian@swagemakers.org","avatar":"https://gravatar.com/avatar/61b8010bc77390da6713f1622e3276430152d11cd512c11c1c241716991a358b?d=mp&s=160"},"body":"Manually send SMTP AUTH command for auth type OAUTHBEARER and XOAUTH2.\nThis is necessary since they are currently not supported by the Perls\nAuthen::SASL module.\n\nThe bearer token needs to be passed in as the password. This can be done\nwith git-credential-oauth[0] after minor modifications[1]. Which will\nallow using git send-email with Gmail and oauth2 authentication:\n\n```\n[credential]\n\thelper = cache --timeout 7200\t# two hours\n\thelper = oauth\n[sendemail]\n    smtpEncryption = tls\n    smtpServer = smtp.gmail.com\n    smtpUser = example@gmail.com\n    smtpServerPort = 587\n    smtpauth = OAUTHBEARER\n```\n\nAs well as Office 365 accounts:\n\n```\n[credential]\n\thelper = cache --timeout 7200\t# two hours\n\thelper = oauth\n[sendemail]\n    smtpEncryption = tls\n    smtpServer = smtp.office365.com\n    smtpUser = example@example.com\n    smtpServerPort = 587\n    smtpauth = XOAUTH2\n```\n\n[0] https://github.com/hickford/git-credential-oauth\n[1] https://github.com/hickford/git-credential-oauth/issues/48\n\nSigned-off-by: Julian Swagemakers <julian@swagemakers.org>\n---\n git-send-email.perl | 65 +++++++++++++++++++++++++++++++++++++++++++--\n 1 file changed, 63 insertions(+), 2 deletions(-)\n\ndiff --git a/git-send-email.perl b/git-send-email.perl\nindex 821b2b3a13..72d378f6fd 100755\n--- a/git-send-email.perl\n+++ b/git-send-email.perl\n@@ -1359,6 +1359,63 @@ sub smtp_host_string {\n \t}\n }\n \n+sub generate_oauthbearer_string {\n+\t# This will generate the oauthbearer string used for authentication.\n+\t#\n+\t# \"n,a=\" {User} \",^Ahost=\" {Host} \"^Aport=\" {Port} \"^Aauth=Bearer \" {Access Token} \"^A^A\n+\t#\n+\t# The first part `n,a=\" {User} \",` is the gs2 header described in RFC5801.\n+\t# * gs2-cb-flag `n` -> client does not support CB\n+\t# * gs2-authzid `a=\" {User} \"`\n+\t#\n+\t# The second part are key value pairs containing host, port and auth as\n+\t# described in RFC7628.\n+\t#\n+\t# https://datatracker.ietf.org/doc/html/rfc5801\n+\t# https://datatracker.ietf.org/doc/html/rfc7628\n+\tmy $username = shift;\n+\tmy $token = shift;\n+\treturn \"n,a=$username,\\001port=$smtp_server_port\\001auth=Bearer $token\\001\\001\";\n+}\n+\n+sub generate_xoauth2_string {\n+\t# \"user=\" {User} \"^Aauth=Bearer \" {Access Token} \"^A^A\"\n+\t# https://developers.google.com/gmail/imap/xoauth2-protocol#initial_client_response\n+\tmy $username = shift;\n+\tmy $token = shift;\n+\treturn \"user=$username\\001auth=Bearer $token\\001\\001\";\n+}\n+\n+sub smtp_bearer_auth {\n+\tmy $username = shift;\n+\tmy $token = shift;\n+\tmy $auth_string;\n+\tif ($smtp_encryption ne \"tls\") {\n+\t\t# As described in RFC7628 TLS is required and will be will\n+\t\t# be enforced at this point.\n+\t\t#\n+\t\t# https://datatracker.ietf.org/doc/html/rfc7628#section-3\n+\t\tdie __(\"For $smtp_auth TLS is required.\")\n+\t}\n+\tif ($smtp_auth eq \"OAUTHBEARER\") {\n+\t\t$auth_string = generate_oauthbearer_string($username, $token);\n+\t} elsif ($smtp_auth eq \"XOAUTH2\") {\n+\t\t$auth_string = generate_xoauth2_string($username, $token);\n+\t}\n+\tmy $encoded_auth_string = MIME::Base64::encode($auth_string, \"\");\n+\t$smtp->command(\"AUTH $smtp_auth $encoded_auth_string\\r\\n\");\n+\tuse Net::Cmd qw(CMD_OK);\n+\tif ($smtp->response() == CMD_OK){\n+\t\treturn 1;\n+\t} else {\n+\t\t# Send dummy request on authentication failure according to rfc7628.\n+\t\t# https://datatracker.ietf.org/doc/html/rfc7628#section-3.2.3\n+\t\t$smtp->command(MIME::Base64::encode(\"\\001\"));\n+\t\t$smtp->response();\n+\t\treturn 0;\n+\t}\n+}\n+\n # Returns 1 if authentication succeeded or was not necessary\n # (smtp_user was not specified), and 0 otherwise.\n \n@@ -1392,8 +1449,12 @@ sub smtp_auth_maybe {\n \t\t'password' => $smtp_authpass\n \t}, sub {\n \t\tmy $cred = shift;\n-\n-\t\tif ($smtp_auth) {\n+\t\tif ($smtp_auth eq \"OAUTHBEARER\" or $smtp_auth eq \"XOAUTH2\") {\n+\t\t\t# Since Authen:SASL does not support XOAUTH2 nor OAUTHBEARER we will\n+\t\t\t# manuall authenticate for tese types. The password field should\n+\t\t\t# contain the auth token at this point.\n+\t\t\treturn smtp_bearer_auth($cred->{'username'}, $cred->{'password'});\n+\t\t} elsif ($smtp_auth) {\n \t\t\tmy $sasl = Authen::SASL->new(\n \t\t\t\tmechanism => $smtp_auth,\n \t\t\t\tcallback => {\n-- \n2.43.2\n\n"},{"id":"489621","messageId":"20240228175329.3371-1-mirth.hickford@gmail.com","threadId":"60990","inReplyTo":"20240225103413.9845-1-julian@swagemakers.org","subject":"Re: [PATCH] send-email: implement SMTP bearer authentication","fromName":"M Hickford","fromEmail":"mirth.hickford@gmail.com","sentAt":"2024-02-28T17:53:29Z","receivedAt":"2024-02-28T17:53:33Z","isPatch":true,"sender":{"key":"mirth.hickford@gmail.com","avatar":"https://avatars.githubusercontent.com/u/105314?v=4"},"body":"Neat idea. I recall it was awkward to configure git-send-email to send with\nGmail. I had to configure a security-compromising 'app password' [1][2].\n\nOAuth is a great improvement.\n\n[1] https://support.google.com/mail/answer/185833\n[2] https://security.google.com/settings/security/apppasswords\n\n\n"},{"id":"504856","messageId":"TYCPR01MB843751F88AF98DFDB606B0BE98792@TYCPR01MB8437.jpnprd01.prod.outlook.com","threadId":"60990","inReplyTo":"20240225103413.9845-1-julian@swagemakers.org","subject":"Re: [PATCH] send-email: implement SMTP bearer authentication","fromName":"Shengyu Qu","fromEmail":"wiagn233@outlook.com","sentAt":"2024-10-11T17:48:18Z","receivedAt":"2024-10-11T17:48:24Z","isPatch":true,"sender":{"key":"wiagn233@outlook.com","avatar":null},"body":"Hello,\n\nSorry to bother but what had happened to this patch? It is more useful now\nsince outlook also switched to oauth2 only mode.\n\nBest regards,\nShengyu\n\n\n在 2024/2/25 18:34, Julian Swagemakers 写道:\n> Manually send SMTP AUTH command for auth type OAUTHBEARER and XOAUTH2.\n> This is necessary since they are currently not supported by the Perls\n> Authen::SASL module.\n>\n> The bearer token needs to be passed in as the password. This can be done\n> with git-credential-oauth[0] after minor modifications[1]. Which will\n> allow using git send-email with Gmail and oauth2 authentication:\n>\n> ```\n> [credential]\n> \thelper = cache --timeout 7200\t# two hours\n> \thelper = oauth\n> [sendemail]\n>      smtpEncryption = tls\n>      smtpServer = smtp.gmail.com\n>      smtpUser = example@gmail.com\n>      smtpServerPort = 587\n>      smtpauth = OAUTHBEARER\n> ```\n>\n> As well as Office 365 accounts:\n>\n> ```\n> [credential]\n> \thelper = cache --timeout 7200\t# two hours\n> \thelper = oauth\n> [sendemail]\n>      smtpEncryption = tls\n>      smtpServer = smtp.office365.com\n>      smtpUser = example@example.com\n>      smtpServerPort = 587\n>      smtpauth = XOAUTH2\n> ```\n>\n> [0] https://github.com/hickford/git-credential-oauth\n> [1] https://github.com/hickford/git-credential-oauth/issues/48\n>\n> Signed-off-by: Julian Swagemakers <julian@swagemakers.org>\n> ---\n>   git-send-email.perl | 65 +++++++++++++++++++++++++++++++++++++++++++--\n>   1 file changed, 63 insertions(+), 2 deletions(-)\n>\n> diff --git a/git-send-email.perl b/git-send-email.perl\n> index 821b2b3a13..72d378f6fd 100755\n> --- a/git-send-email.perl\n> +++ b/git-send-email.perl\n> @@ -1359,6 +1359,63 @@ sub smtp_host_string {\n>   \t}\n>   }\n>   \n> +sub generate_oauthbearer_string {\n> +\t# This will generate the oauthbearer string used for authentication.\n> +\t#\n> +\t# \"n,a=\" {User} \",^Ahost=\" {Host} \"^Aport=\" {Port} \"^Aauth=Bearer \" {Access Token} \"^A^A\n> +\t#\n> +\t# The first part `n,a=\" {User} \",` is the gs2 header described in RFC5801.\n> +\t# * gs2-cb-flag `n` -> client does not support CB\n> +\t# * gs2-authzid `a=\" {User} \"`\n> +\t#\n> +\t# The second part are key value pairs containing host, port and auth as\n> +\t# described in RFC7628.\n> +\t#\n> +\t# https://datatracker.ietf.org/doc/html/rfc5801\n> +\t# https://datatracker.ietf.org/doc/html/rfc7628\n> +\tmy $username = shift;\n> +\tmy $token = shift;\n> +\treturn \"n,a=$username,\\001port=$smtp_server_port\\001auth=Bearer $token\\001\\001\";\n> +}\n> +\n> +sub generate_xoauth2_string {\n> +\t# \"user=\" {User} \"^Aauth=Bearer \" {Access Token} \"^A^A\"\n> +\t# https://developers.google.com/gmail/imap/xoauth2-protocol#initial_client_response\n> +\tmy $username = shift;\n> +\tmy $token = shift;\n> +\treturn \"user=$username\\001auth=Bearer $token\\001\\001\";\n> +}\n> +\n> +sub smtp_bearer_auth {\n> +\tmy $username = shift;\n> +\tmy $token = shift;\n> +\tmy $auth_string;\n> +\tif ($smtp_encryption ne \"tls\") {\n> +\t\t# As described in RFC7628 TLS is required and will be will\n> +\t\t# be enforced at this point.\n> +\t\t#\n> +\t\t# https://datatracker.ietf.org/doc/html/rfc7628#section-3\n> +\t\tdie __(\"For $smtp_auth TLS is required.\")\n> +\t}\n> +\tif ($smtp_auth eq \"OAUTHBEARER\") {\n> +\t\t$auth_string = generate_oauthbearer_string($username, $token);\n> +\t} elsif ($smtp_auth eq \"XOAUTH2\") {\n> +\t\t$auth_string = generate_xoauth2_string($username, $token);\n> +\t}\n> +\tmy $encoded_auth_string = MIME::Base64::encode($auth_string, \"\");\n> +\t$smtp->command(\"AUTH $smtp_auth $encoded_auth_string\\r\\n\");\n> +\tuse Net::Cmd qw(CMD_OK);\n> +\tif ($smtp->response() == CMD_OK){\n> +\t\treturn 1;\n> +\t} else {\n> +\t\t# Send dummy request on authentication failure according to rfc7628.\n> +\t\t# https://datatracker.ietf.org/doc/html/rfc7628#section-3.2.3\n> +\t\t$smtp->command(MIME::Base64::encode(\"\\001\"));\n> +\t\t$smtp->response();\n> +\t\treturn 0;\n> +\t}\n> +}\n> +\n>   # Returns 1 if authentication succeeded or was not necessary\n>   # (smtp_user was not specified), and 0 otherwise.\n>   \n> @@ -1392,8 +1449,12 @@ sub smtp_auth_maybe {\n>   \t\t'password' => $smtp_authpass\n>   \t}, sub {\n>   \t\tmy $cred = shift;\n> -\n> -\t\tif ($smtp_auth) {\n> +\t\tif ($smtp_auth eq \"OAUTHBEARER\" or $smtp_auth eq \"XOAUTH2\") {\n> +\t\t\t# Since Authen:SASL does not support XOAUTH2 nor OAUTHBEARER we will\n> +\t\t\t# manuall authenticate for tese types. The password field should\n> +\t\t\t# contain the auth token at this point.\n> +\t\t\treturn smtp_bearer_auth($cred->{'username'}, $cred->{'password'});\n> +\t\t} elsif ($smtp_auth) {\n>   \t\t\tmy $sasl = Authen::SASL->new(\n>   \t\t\t\tmechanism => $smtp_auth,\n>   \t\t\t\tcallback => {\n\n"},{"id":"504864","messageId":"xmqqed4mecrq.fsf@gitster.g","threadId":"60990","inReplyTo":"TYCPR01MB843751F88AF98DFDB606B0BE98792@TYCPR01MB8437.jpnprd01.prod.outlook.com","subject":"Re: [PATCH] send-email: implement SMTP bearer authentication","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2024-10-11T18:05:13Z","receivedAt":"2024-10-11T18:05:16Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Shengyu Qu <wiagn233@outlook.com> writes:\n\n> Sorry to bother but what had happened to this patch? It is more useful now\n> since outlook also switched to oauth2 only mode.\n\nYou are the second person to mention that what the change wants to\ndo is sensible, but nobody gave any review that verified that the\nchange does what the change says it wants to do, so it was left in\nthe mailing list archive.\n\nThanks for pinging.  Perhaps it would remind and encourage others\n(or even better, yourself) to review the patch to help it move\nforward.\n"},{"id":"504868","messageId":"TYCPR01MB8437CDD2208EA6555117E72C98792@TYCPR01MB8437.jpnprd01.prod.outlook.com","threadId":"60990","inReplyTo":"xmqqed4mecrq.fsf@gitster.g","subject":"Re: [PATCH] send-email: implement SMTP bearer authentication","fromName":"Shengyu Qu","fromEmail":"wiagn233@outlook.com","sentAt":"2024-10-11T18:24:57Z","receivedAt":"2024-10-11T18:25:02Z","isPatch":true,"sender":{"key":"wiagn233@outlook.com","avatar":null},"body":"Hello Junio,\n\nSeems you didn't CCed all relative people about this patch so that\nmaintainers about this file might didn't notice this patch, you can try\nthe script mentioned here[1] and resend this patch.\n\nBest regards,\nShengyu\n\n[1] https://git-scm.com/docs/SubmittingPatches#send-patches\n\n在 2024/10/12 2:05, Junio C Hamano 写道:\n> Shengyu Qu <wiagn233@outlook.com> writes:\n> \n>> Sorry to bother but what had happened to this patch? It is more useful now\n>> since outlook also switched to oauth2 only mode.\n> \n> You are the second person to mention that what the change wants to\n> do is sensible, but nobody gave any review that verified that the\n> change does what the change says it wants to do, so it was left in\n> the mailing list archive.\n> \n> Thanks for pinging.  Perhaps it would remind and encourage others\n> (or even better, yourself) to review the patch to help it move\n> forward.\n\n"},{"id":"504923","messageId":"D4U1RWVWEW5D.2T853XSBO1FPA@swagemakers.org","threadId":"60990","inReplyTo":"TYCPR01MB8437CDD2208EA6555117E72C98792@TYCPR01MB8437.jpnprd01.prod.outlook.com","subject":"Re: [PATCH] send-email: implement SMTP bearer authentication","fromName":"Julian Swagemakers","fromEmail":"julian@swagemakers.org","sentAt":"2024-10-12T18:43:10Z","receivedAt":"2024-10-12T18:43:19Z","isPatch":true,"sender":{"key":"julian@swagemakers.org","avatar":"https://gravatar.com/avatar/61b8010bc77390da6713f1622e3276430152d11cd512c11c1c241716991a358b?d=mp&s=160"},"body":"Hi Shengyu,\n\n> Seems you didn't CCed all relative people about this patch so that\n> maintainers about this file might didn't notice this patch, you can try\n> the script mentioned here[1] and resend this patch.\n\nI did see that, but the output is just Junio, and I assumed as he is the\nmaintainer, he would be following the list and did not need the extra\nCC. I don't know who else could be interested in this patch and is\nwilling to test and review it.\n\nRegards Julian\n"},{"id":"511201","messageId":"20250125190131.48717-1-julian@swagemakers.org","threadId":"60990","inReplyTo":"20240225103413.9845-1-julian@swagemakers.org","subject":"[PATCH v2] send-email: implement SMTP bearer authentication","fromName":"Julian Swagemakers","fromEmail":"julian@swagemakers.org","sentAt":"2025-01-25T19:01:31Z","receivedAt":"2025-01-25T19:02:09Z","isPatch":true,"sender":{"key":"julian@swagemakers.org","avatar":"https://gravatar.com/avatar/61b8010bc77390da6713f1622e3276430152d11cd512c11c1c241716991a358b?d=mp&s=160"},"body":"Manually send SMTP AUTH command for auth type OAUTHBEARER and XOAUTH2.\nThis is necessary since they are currently not supported by the Perls\nAuthen::SASL module.\n\nThe bearer token needs to be passed in as the password. This can be done\nwith git-credential-oauth[0] after minor modifications[1]. Which will\nallow using git send-email with Gmail and oauth2 authentication:\n\n    [credential]\n        helper = cache --timeout 7200    # two hours\n        helper = oauth\n    [sendemail]\n        smtpEncryption = tls\n        smtpServer = smtp.gmail.com\n        smtpUser = example@gmail.com\n        smtpServerPort = 587\n        smtpauth = OAUTHBEARER\n\nAs well as Office 365 accounts:\n\n    [credential]\n        helper = cache --timeout 7200   # two hours\n        helper = oauth\n    [sendemail]\n        smtpEncryption = tls\n        smtpServer = smtp.office365.com\n        smtpUser = example@example.com\n        smtpServerPort = 587\n        smtpauth = XOAUTH2\n\n[0] https://github.com/hickford/git-credential-oauth\n[1] https://github.com/hickford/git-credential-oauth/issues/48\n\nTested-by: M Hickford <mirth.hickford@gmail.com>\nSigned-off-by: Julian Swagemakers <julian@swagemakers.org>\n---\n Documentation/git-send-email.txt |  5 ++-\n git-send-email.perl              | 65 +++++++++++++++++++++++++++++++-\n 2 files changed, 67 insertions(+), 3 deletions(-)\n\ndiff --git a/Documentation/git-send-email.txt b/Documentation/git-send-email.txt\nindex bc3ef45acb..b1972d99bf 100644\n--- a/Documentation/git-send-email.txt\n+++ b/Documentation/git-send-email.txt\n@@ -213,7 +213,10 @@ SMTP server and if it is supported by the utilized SASL library, the mechanism\n is used for authentication. If neither 'sendemail.smtpAuth' nor `--smtp-auth`\n is specified, all mechanisms supported by the SASL library can be used. The\n special value 'none' maybe specified to completely disable authentication\n-independently of `--smtp-user`\n+independently of `--smtp-user`. Specifying `OAUTHBEARER` or `XOAUTH2` will\n+bypass SASL negotiation and force bearer authentication. In this case the\n+bearer token must be provided with `--smtp-pass` or using a credential helper\n+and `--smtp-encryption=tls` must be set.\n \n --smtp-pass[=<password>]::\n \tPassword for SMTP-AUTH. The argument is optional: If no\ndiff --git a/git-send-email.perl b/git-send-email.perl\nindex 798d59b84f..a78159971b 100755\n--- a/git-send-email.perl\n+++ b/git-send-email.perl\n@@ -1398,6 +1398,63 @@ sub smtp_host_string {\n \t}\n }\n \n+sub generate_oauthbearer_string {\n+\t# This will generate the oauthbearer string used for authentication.\n+\t#\n+\t# \"n,a=\" {User} \",^Ahost=\" {Host} \"^Aport=\" {Port} \"^Aauth=Bearer \" {Access Token} \"^A^A\n+\t#\n+\t# The first part `n,a=\" {User} \",` is the gs2 header described in RFC5801.\n+\t# * gs2-cb-flag `n` -> client does not support CB\n+\t# * gs2-authzid `a=\" {User} \"`\n+\t#\n+\t# The second part are key value pairs containing host, port and auth as\n+\t# described in RFC7628.\n+\t#\n+\t# https://datatracker.ietf.org/doc/html/rfc5801\n+\t# https://datatracker.ietf.org/doc/html/rfc7628\n+\tmy $username = shift;\n+\tmy $token = shift;\n+\treturn \"n,a=$username,\\001port=$smtp_server_port\\001auth=Bearer $token\\001\\001\";\n+}\n+\n+sub generate_xoauth2_string {\n+\t# \"user=\" {User} \"^Aauth=Bearer \" {Access Token} \"^A^A\"\n+\t# https://developers.google.com/gmail/imap/xoauth2-protocol#initial_client_response\n+\tmy $username = shift;\n+\tmy $token = shift;\n+\treturn \"user=$username\\001auth=Bearer $token\\001\\001\";\n+}\n+\n+sub smtp_bearer_auth {\n+\tmy $username = shift;\n+\tmy $token = shift;\n+\tmy $auth_string;\n+\tif ($smtp_encryption ne \"tls\") {\n+\t\t# As described in RFC7628 TLS is required and will be enforced\n+\t\t# at this point.\n+\t\t#\n+\t\t# https://datatracker.ietf.org/doc/html/rfc7628#section-3\n+\t\tdie __(\"For $smtp_auth TLS is required.\")\n+\t}\n+\tif ($smtp_auth eq \"OAUTHBEARER\") {\n+\t\t$auth_string = generate_oauthbearer_string($username, $token);\n+\t} elsif ($smtp_auth eq \"XOAUTH2\") {\n+\t\t$auth_string = generate_xoauth2_string($username, $token);\n+\t}\n+\tmy $encoded_auth_string = MIME::Base64::encode($auth_string, \"\");\n+\t$smtp->command(\"AUTH $smtp_auth $encoded_auth_string\\r\\n\");\n+\tuse Net::Cmd qw(CMD_OK);\n+\tif ($smtp->response() == CMD_OK){\n+\t\treturn 1;\n+\t} else {\n+\t\t# Send dummy request on authentication failure according to rfc7628.\n+\t\t# https://datatracker.ietf.org/doc/html/rfc7628#section-3.2.3\n+\t\t$smtp->command(MIME::Base64::encode(\"\\001\"));\n+\t\t$smtp->response();\n+\t\treturn 0;\n+\t}\n+}\n+\n # Returns 1 if authentication succeeded or was not necessary\n # (smtp_user was not specified), and 0 otherwise.\n \n@@ -1431,8 +1488,12 @@ sub smtp_auth_maybe {\n \t\t'password' => $smtp_authpass\n \t}, sub {\n \t\tmy $cred = shift;\n-\n-\t\tif ($smtp_auth) {\n+\t\tif (defined $smtp_auth && ($smtp_auth eq \"OAUTHBEARER\" || $smtp_auth eq \"XOAUTH2\")) {\n+\t\t\t# Since Authen:SASL does not support XOAUTH2 nor OAUTHBEARER we will\n+\t\t\t# manually authenticate for these types. The password field should\n+\t\t\t# contain the auth token at this point.\n+\t\t\treturn smtp_bearer_auth($cred->{'username'}, $cred->{'password'});\n+\t\t} elsif ($smtp_auth) {\n \t\t\tmy $sasl = Authen::SASL->new(\n \t\t\t\tmechanism => $smtp_auth,\n \t\t\t\tcallback => {\n\nRange-diff against v1:\n1:  ab3ba94099 ! 1:  7532a1ee0a send-email: implement SMTP bearer authentication\n    @@ Commit message\n         with git-credential-oauth[0] after minor modifications[1]. Which will\n         allow using git send-email with Gmail and oauth2 authentication:\n     \n    -    ```\n    -    [credential]\n    -            helper = cache --timeout 7200   # two hours\n    +        [credential]\n    +            helper = cache --timeout 7200    # two hours\n                 helper = oauth\n    -    [sendemail]\n    -        smtpEncryption = tls\n    -        smtpServer = smtp.gmail.com\n    -        smtpUser = example@gmail.com\n    -        smtpServerPort = 587\n    -        smtpauth = OAUTHBEARER\n    -    ```\n    +        [sendemail]\n    +            smtpEncryption = tls\n    +            smtpServer = smtp.gmail.com\n    +            smtpUser = example@gmail.com\n    +            smtpServerPort = 587\n    +            smtpauth = OAUTHBEARER\n     \n         As well as Office 365 accounts:\n     \n    -    ```\n    -    [credential]\n    +        [credential]\n                 helper = cache --timeout 7200   # two hours\n                 helper = oauth\n    -    [sendemail]\n    -        smtpEncryption = tls\n    -        smtpServer = smtp.office365.com\n    -        smtpUser = example@example.com\n    -        smtpServerPort = 587\n    -        smtpauth = XOAUTH2\n    -    ```\n    +        [sendemail]\n    +            smtpEncryption = tls\n    +            smtpServer = smtp.office365.com\n    +            smtpUser = example@example.com\n    +            smtpServerPort = 587\n    +            smtpauth = XOAUTH2\n     \n         [0] https://github.com/hickford/git-credential-oauth\n         [1] https://github.com/hickford/git-credential-oauth/issues/48\n     \n    +    Tested-by: M Hickford <mirth.hickford@gmail.com>\n         Signed-off-by: Julian Swagemakers <julian@swagemakers.org>\n     \n    + ## Documentation/git-send-email.txt ##\n    +@@ Documentation/git-send-email.txt: SMTP server and if it is supported by the utilized SASL library, the mechanism\n    + is used for authentication. If neither 'sendemail.smtpAuth' nor `--smtp-auth`\n    + is specified, all mechanisms supported by the SASL library can be used. The\n    + special value 'none' maybe specified to completely disable authentication\n    +-independently of `--smtp-user`\n    ++independently of `--smtp-user`. Specifying `OAUTHBEARER` or `XOAUTH2` will\n    ++bypass SASL negotiation and force bearer authentication. In this case the\n    ++bearer token must be provided with `--smtp-pass` or using a credential helper\n    ++and `--smtp-encryption=tls` must be set.\n    + \n    + --smtp-pass[=<password>]::\n    + \tPassword for SMTP-AUTH. The argument is optional: If no\n    +\n      ## git-send-email.perl ##\n     @@ git-send-email.perl: sub smtp_host_string {\n      \t}\n    @@ git-send-email.perl: sub smtp_host_string {\n     +\tmy $token = shift;\n     +\tmy $auth_string;\n     +\tif ($smtp_encryption ne \"tls\") {\n    -+\t\t# As described in RFC7628 TLS is required and will be will\n    -+\t\t# be enforced at this point.\n    ++\t\t# As described in RFC7628 TLS is required and will be enforced\n    ++\t\t# at this point.\n     +\t\t#\n     +\t\t# https://datatracker.ietf.org/doc/html/rfc7628#section-3\n     +\t\tdie __(\"For $smtp_auth TLS is required.\")\n    @@ git-send-email.perl: sub smtp_auth_maybe {\n      \t\tmy $cred = shift;\n     -\n     -\t\tif ($smtp_auth) {\n    -+\t\tif ($smtp_auth eq \"OAUTHBEARER\" or $smtp_auth eq \"XOAUTH2\") {\n    ++\t\tif (defined $smtp_auth && ($smtp_auth eq \"OAUTHBEARER\" || $smtp_auth eq \"XOAUTH2\")) {\n     +\t\t\t# Since Authen:SASL does not support XOAUTH2 nor OAUTHBEARER we will\n    -+\t\t\t# manuall authenticate for tese types. The password field should\n    ++\t\t\t# manually authenticate for these types. The password field should\n     +\t\t\t# contain the auth token at this point.\n     +\t\t\treturn smtp_bearer_auth($cred->{'username'}, $cred->{'password'});\n     +\t\t} elsif ($smtp_auth) {\n-- \n2.48.1\n\n"}]}