Re: [PATCH v1] send-email: provide whitelist of SMTP AUTH mechanisms
- From
brian m. carlson <sandals@crustytoothpaste.net>
- Date
- Aug 1, 2015, 16:49 UTC
- Message-ID
- <20150801164959.GC488564@vauxhall.crustytoothpaste.net>
- In-Reply-To
- <1438385617-29159-1-git-send-email-viktorin@rehivetech.com>
On Sat, Aug 01, 2015 at 01:33:37AM +0200, Jan Viktorin wrote:
> + # Do not allow arbitrary strings.
> + my ($filtered_auth) = "";
> + foreach ("PLAIN", "LOGIN", "CRAM-MD5", "DIGEST-MD5") {On my system, GSSAPI is also available, and it does indeed work, as I'm not prompted for a password. (I have only PLAIN and GSSAPI available server-side, and AUTH is required.)
It may be better to simply force the text to upper case, as that would allow us not to have to change Git if Authen::SASL::Perl implements new mechanisms.
-- brian m. carlson / brian with sandals: Houston, Texas, US +1 832 623 2791 | http://www.crustytoothpaste.net/~bmc | My opinion only OpenPGP: RSA v4 4096b: 88AC E9B2 9196 305B A994 7552 F1BA 225C 0223 B187