git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2] send-email: provide whitelist of SMTP AUTH mechanisms

From
Eric Sunshine <sunshine@sunshineco.com>
Date
Aug 10, 2015, 23:43 UTC
Message-ID
<CAPig+cSU_rgRvfETfY7TiY6X0B6Tt6N0+GMVgSsYH-6zMteAgg@mail.gmail.com>
In-Reply-To
<20150810120642.2a0baac2@jvn>
On Mon, Aug 10, 2015 at 6:06 AM, Jan Viktorin <viktorin@rehivetech.com> wrote:
Show 14 quoted lines
> On Sun, 9 Aug 2015 14:13:33 -0400
> Eric Sunshine <sunshine@sunshineco.com> wrote:
>> One possibility which comes to mind is to create a fake
>> Authen::SASL::Perl which merely dumps its input mechanisms to a file,
>> and arrange for the Perl search path to find the fake one instead. You
>> could then check the output file to see if it reflects your
>> expectations. However, this may be overkill and perhaps not worth the
>> effort (especially if you're not a Perl programmer).
>
> I think that Authen::SASL::Perl mock would not help. I wanted to create
> some fake sendmail (but this is impossible as stated above because
> then the perl modules are not used). So the only way would be to
> provide some fake socket with a static content on the other side. This
> is really an overkill to just test the few lines of code.
Agreed.
> So, what more can I do for this feature?

I don't have any further suggestions. Other than the unwanted "Supported:" line in the documentation and the couple style issues[1], the patch seems sufficiently complete, as-is. The validation regex gets a "meh" from me merely because it's not clear how beneficial it will be in practice, but that's not an outright objection; I don't feel strongly about it either way.

[1]: http://article.gmane.org/gmane.comp.version-control.git/275150
Show 5 quoted lines
> I think that the basic regex test is OK. It can accept lowercase
> letters and do an explicit uppercase call. I do not like to rely on
> internals of the SASL library. As you could see, the SASL::Perl does
> not check its inputs in a very good way and its code is quite unclear
> (strange for a library providing security features).
Previous: Jan ViktorinNext: Eric Sunshine
Message 6 of 10 in “send-email: provide whitelist of SMTP AUTH mechanisms”
  1. send-email: provide whitelist of SMTP AUTH mechanismsJan Viktorin, Aug 2, 2015
  2. Eric SunshineAug 2, 2015
  3. Jan ViktorinAug 5, 2015
  4. Eric SunshineAug 9, 2015
  5. Jan ViktorinAug 10, 2015
  6. Eric SunshineAug 10, 2015
  7. Eric SunshineAug 9, 2015
  8. Eric SunshineAug 9, 2015
  9. send-email: provide whitelist of SMTP AUTH mechanismsJan Viktorin, Aug 11, 2015
  10. Eric SunshineAug 12, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.