git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v1] send-email: provide whitelist of SMTP AUTH mechanisms

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Aug 1, 2015, 16:49 UTC
Message-ID
<20150801164959.GC488564@vauxhall.crustytoothpaste.net>
In-Reply-To
<1438385617-29159-1-git-send-email-viktorin@rehivetech.com>
On Sat, Aug 01, 2015 at 01:33:37AM +0200, Jan Viktorin wrote:
> +	# Do not allow arbitrary strings.
> +	my ($filtered_auth) = "";
> +	foreach ("PLAIN", "LOGIN", "CRAM-MD5", "DIGEST-MD5") {

On my system, GSSAPI is also available, and it does indeed work, as I'm not prompted for a password. (I have only PLAIN and GSSAPI available server-side, and AUTH is required.)

It may be better to simply force the text to upper case, as that would allow us not to have to change Git if Authen::SASL::Perl implements new mechanisms.

-- 
brian m. carlson / brian with sandals: Houston, Texas, US
+1 832 623 2791 | http://www.crustytoothpaste.net/~bmc | My opinion only
OpenPGP: RSA v4 4096b: 88AC E9B2 9196 305B A994 7552 F1BA 225C 0223 B187
Previous: Junio C HamanoNext: Jan Viktorin
Message 10 of 11 in “send-email: provide whitelist of SMTP AUTH mechanisms”
  1. send-email: provide whitelist of SMTP AUTH mechanismsJan Viktorin, Jul 31, 2015
  2. Eric SunshineAug 1, 2015
  3. Jan ViktorinAug 1, 2015
  4. Eric SunshineAug 2, 2015
  5. Jan ViktorinAug 2, 2015
  6. Junio C HamanoAug 2, 2015
  7. Jan ViktorinAug 3, 2015
  8. Junio C HamanoAug 3, 2015
  9. Junio C HamanoAug 2, 2015
  10. brian m. carlsonAug 1, 2015
  11. Jan ViktorinAug 1, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.