git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v1] send-email: provide whitelist of SMTP AUTH mechanisms

From
JVJan Viktorin <viktorin@rehivetech.com>
Date
Aug 1, 2015, 18:21 UTC
Message-ID
<20150801202156.57debcc3@jvn>
In-Reply-To
<20150801164959.GC488564@vauxhall.crustytoothpaste.net>
Hello Brian,

thanks for your note. I think, I will remove the check of list of mechanisms and put there a regex check.

On Sat, 1 Aug 2015 16:49:59 +0000 "brian m. carlson" <sandals@crustytoothpaste.net> wrote:

Show 12 quoted lines
> On Sat, Aug 01, 2015 at 01:33:37AM +0200, Jan Viktorin wrote:
> > +	# Do not allow arbitrary strings.
> > +	my ($filtered_auth) = "";
> > +	foreach ("PLAIN", "LOGIN", "CRAM-MD5", "DIGEST-MD5") {
> 
> On my system, GSSAPI is also available, and it does indeed work, as
> I'm not prompted for a password.  (I have only PLAIN and GSSAPI
> available server-side, and AUTH is required.)
> 
> It may be better to simply force the text to upper case, as that would
> allow us not to have to change Git if Authen::SASL::Perl implements
> new mechanisms.
-- 
  Jan Viktorin                E-mail: Viktorin@RehiveTech.com
  System Architect            Web:    www.RehiveTech.com
  RehiveTech                  Phone: +420 606 201 868
  Brno, Czech Republic
Previous: brian m. carlson
Message 11 of 11 in “send-email: provide whitelist of SMTP AUTH mechanisms”
  1. send-email: provide whitelist of SMTP AUTH mechanismsJan Viktorin, Jul 31, 2015
  2. Eric SunshineAug 1, 2015
  3. Jan ViktorinAug 1, 2015
  4. Eric SunshineAug 2, 2015
  5. Jan ViktorinAug 2, 2015
  6. Junio C HamanoAug 2, 2015
  7. Jan ViktorinAug 3, 2015
  8. Junio C HamanoAug 3, 2015
  9. Junio C HamanoAug 2, 2015
  10. brian m. carlsonAug 1, 2015
  11. Jan ViktorinAug 1, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.