threads / patch / 23201

patchimap-send: suppress warning about cleartext password with CRAM-MD5

Subject: [PATCH] imap-send: suppress warning about cleartext password with CRAM-MD5

## tl;dr

3 messages between Mar 27, 2010 and Mar 30, 2010. Diffs are folded; open one to read it.

replies: 2people: 3as markdown or json

Chris Webb· Mar 27, 2010, 15:00 UTC · lore

If a CRAM-MD5 challenge-response is used to authenticate to the IMAP server, git imap-send shouldn't warn about the password being sent in the clear.

Signed-off-by: Chris Webb <chris@arachsys.com>
---
 imap-send.c |    6 +++---
 1 files changed, 3 insertions(+), 3 deletions(-)
Show changes to imap-send.c +3 −3
diff --git a/imap-send.c b/imap-send.c
index aeb2985..7107923 100644
--- a/imap-send.c
+++ b/imap-send.c
@@ -1226,9 +1226,6 @@ static struct store *imap_open_store(struct imap_server_conf *srvc)
 			fprintf(stderr, "Skipping account %s@%s, server forbids LOGIN\n", srvc->user, srvc->host);
 			goto bail;
 		}
-		if (!imap->buf.sock.ssl)
-			imap_warn("*** IMAP Warning *** Password is being "
-				  "sent in the clear\n");
 
 		if (srvc->auth_method) {
 			struct imap_cmd_cb cb;
@@ -1253,6 +1250,9 @@ static struct store *imap_open_store(struct imap_server_conf *srvc)
 				goto bail;
 			}
 		} else {
+			if (!imap->buf.sock.ssl)
+				imap_warn("*** IMAP Warning *** Password is being "
+					  "sent in the clear\n");
 			if (imap_exec(ctx, NULL, "LOGIN \"%s\" \"%s\"", srvc->user, srvc->pass) != RESP_OK) {
 				fprintf(stderr, "IMAP error: LOGIN failed\n");
 				goto bail;
-- 
1.7.0.1
Junio C Hamano· Mar 28, 2010, 16:25 UTC · re: Chris Webb · lore

Re: [PATCH] imap-send: suppress warning about cleartext password with CRAM-MD5

Chris Webb <chris@arachsys.com> writes:
Show 5 quoted lines
> If a CRAM-MD5 challenge-response is used to authenticate to the IMAP server,
> git imap-send shouldn't warn about the password being sent in the clear.
>
> Signed-off-by: Chris Webb <chris@arachsys.com>
> ---
Makes sense.  Thanks.
Show 29 quoted lines
>  imap-send.c |    6 +++---
>  1 files changed, 3 insertions(+), 3 deletions(-)
>
> diff --git a/imap-send.c b/imap-send.c
> index aeb2985..7107923 100644
> --- a/imap-send.c
> +++ b/imap-send.c
> @@ -1226,9 +1226,6 @@ static struct store *imap_open_store(struct imap_server_conf *srvc)
>  			fprintf(stderr, "Skipping account %s@%s, server forbids LOGIN\n", srvc->user, srvc->host);
>  			goto bail;
>  		}
> -		if (!imap->buf.sock.ssl)
> -			imap_warn("*** IMAP Warning *** Password is being "
> -				  "sent in the clear\n");
>  
>  		if (srvc->auth_method) {
>  			struct imap_cmd_cb cb;
> @@ -1253,6 +1250,9 @@ static struct store *imap_open_store(struct imap_server_conf *srvc)
>  				goto bail;
>  			}
>  		} else {
> +			if (!imap->buf.sock.ssl)
> +				imap_warn("*** IMAP Warning *** Password is being "
> +					  "sent in the clear\n");
>  			if (imap_exec(ctx, NULL, "LOGIN \"%s\" \"%s\"", srvc->user, srvc->pass) != RESP_OK) {
>  				fprintf(stderr, "IMAP error: LOGIN failed\n");
>  				goto bail;
> -- 
> 1.7.0.1
Hitoshi Mitake· Mar 30, 2010, 10:51 UTC · re: Junio C Hamano · lore

Re: [PATCH] imap-send: suppress warning about cleartext password with CRAM-MD5

On 03/29/10 01:25, Junio C Hamano wrote:
 > Chris Webb<chris@arachsys.com>  writes:
 >
 >> If a CRAM-MD5 challenge-response is used to authenticate to the IMAP 
server,
 >> git imap-send shouldn't warn about the password being sent in the clear.
 >>
 >> Signed-off-by: Chris Webb<chris@arachsys.com>
 >> ---
 >
 > Makes sense.  Thanks.
 >
 >>   imap-send.c |    6 +++---
 >>   1 files changed, 3 insertions(+), 3 deletions(-)
 >>
 >> diff --git a/imap-send.c b/imap-send.c
 >> index aeb2985..7107923 100644
 >> --- a/imap-send.c
 >> +++ b/imap-send.c
 >> @@ -1226,9 +1226,6 @@ static struct store *imap_open_store(struct 
imap_server_conf *srvc)
 >>   			fprintf(stderr, "Skipping account %s@%s, server forbids 
LOGIN\n", srvc->user, srvc->host);
 >>   			goto bail;
 >>   		}
 >> -		if (!imap->buf.sock.ssl)
 >> -			imap_warn("*** IMAP Warning *** Password is being "
 >> -				  "sent in the clear\n");
 >>
 >>   		if (srvc->auth_method) {
 >>   			struct imap_cmd_cb cb;
 >> @@ -1253,6 +1250,9 @@ static struct store *imap_open_store(struct 
imap_server_conf *srvc)
 >>   				goto bail;
 >>   			}
 >>   		} else {
 >> +			if (!imap->buf.sock.ssl)
 >> +				imap_warn("*** IMAP Warning *** Password is being "
 >> +					  "sent in the clear\n");
 >>   			if (imap_exec(ctx, NULL, "LOGIN \"%s\" \"%s\"", srvc->user, 
srvc->pass) != RESP_OK) {
 >>   				fprintf(stderr, "IMAP error: LOGIN failed\n");
 >>   				goto bail;
 >> --
 >> 1.7.0.1
 >

Thanks Chris, this was my mistake. And thanks for your notify, Junio.

     Hitoshi

← back to recent threads