git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v1] send-email: provide whitelist of SMTP AUTH mechanisms

From
Junio C Hamano <gitster@pobox.com>
Date
Aug 2, 2015, 18:28 UTC
Message-ID
<xmqqwpxd8rz2.fsf@gitster.dls.corp.google.com>
In-Reply-To
<20150802184353.2a5da936@jvn>
Jan Viktorin <viktorin@rehivetech.com> writes:
Show 13 quoted lines
> Authen::SASL gives:
>
> No SASL mechanism found
>  at /usr/share/perl5/vendor_perl/Authen/SASL.pm line 77.
>  at /usr/share/perl5/core_perl/Net/SMTP.pm line 207.
>
> The SASL library does not check validity of mechanisms'
> names (or I did not find it). It just tries to load one
> that matches both the ours and the server side ones.
> ...
> I would like to include the regex check based on RFC 4422
> as I've already mentioned. at least, it filters out the
> unwanted characters like '/', '.', etc.

Hmm, is there a way to ask Authen::SASL what SASL mechanism the installed system supports? If so, the enhancement you are adding could be

	my @to_use;
	if ($smtp_auth_whitelist is supplied) {
		my @installed = Authen::SASL::list_mechanisms();
                for (@installed) {
                	if ($_ is whitelisted) {
				push @to_use, $_;
			}
		}
	}

and @to_use can later be supplied when we open the connection as the list of mechanisms we allow the library to pick.

Just my $.02
Previous: Jan ViktorinNext: Jan Viktorin
Message 6 of 11 in “send-email: provide whitelist of SMTP AUTH mechanisms”
  1. send-email: provide whitelist of SMTP AUTH mechanismsJan Viktorin, Jul 31, 2015
  2. Eric SunshineAug 1, 2015
  3. Jan ViktorinAug 1, 2015
  4. Eric SunshineAug 2, 2015
  5. Jan ViktorinAug 2, 2015
  6. Junio C HamanoAug 2, 2015
  7. Jan ViktorinAug 3, 2015
  8. Junio C HamanoAug 3, 2015
  9. Junio C HamanoAug 2, 2015
  10. brian m. carlsonAug 1, 2015
  11. Jan ViktorinAug 1, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.