git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2] send-email: provide whitelist of SMTP AUTH mechanisms

From
Eric Sunshine <sunshine@sunshineco.com>
Date
Aug 9, 2015, 17:19 UTC
Message-ID
<CAPig+cRenkDWeQWR_QFvy_mrH=n5=hz6kaB3PMd_LLbPWN3U1g@mail.gmail.com>
In-Reply-To
<CAPig+cQwFxVtO1C_RAumGP6_et21ggORB4jhpcUtBYNznNH1qA@mail.gmail.com>
On Sun, Aug 2, 2015 at 2:57 PM, Eric Sunshine <sunshine@sunshineco.com> wrote:
Show 10 quoted lines
> On Sun, Aug 2, 2015 at 12:42 PM, Jan Viktorin <viktorin@rehivetech.com> wrote:
>> @@ -1136,6 +1141,10 @@ sub smtp_auth_maybe {
>>                 Authen::SASL->import(qw(Perl));
>>         };
>>
>> +       if($smtp_auth !~ /^(\b[A-Z0-9-_]{1,20}\s*)*$/) {
>> +               die "invalid smtp auth: '${smtp_auth}'";
>> +       }
>
> Style: space after 'if'

By the way, I notice that Authen::SASL::Perl implementation itself normalizes the incoming mechanism to uppercase, if necessary:

    $mechanism =~ s/^\s*\b(.*)\b\s*$/$1/g;
    $mechanism =~ s/-/_/g;
    $mechanism =  uc $mechanism;

Since it doesn't require uppercase, it's not clear how much benefit there is to adding a strict regex check to git-send-email.

Previous: Eric SunshineNext: Eric Sunshine
Message 7 of 10 in “send-email: provide whitelist of SMTP AUTH mechanisms”
  1. send-email: provide whitelist of SMTP AUTH mechanismsJan Viktorin, Aug 2, 2015
  2. Eric SunshineAug 2, 2015
  3. Jan ViktorinAug 5, 2015
  4. Eric SunshineAug 9, 2015
  5. Jan ViktorinAug 10, 2015
  6. Eric SunshineAug 10, 2015
  7. Eric SunshineAug 9, 2015
  8. Eric SunshineAug 9, 2015
  9. send-email: provide whitelist of SMTP AUTH mechanismsJan Viktorin, Aug 11, 2015
  10. Eric SunshineAug 12, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.