# [PATCH] imap-send: suppress warning about cleartext password with CRAM-MD5

3 messages from 2010-03-27 to 2010-03-30. Participants: Chris Webb, Junio C Hamano, Hitoshi Mitake.
Thread: https://gitlist.dev/t/23201

## Chris Webb, 2010-03-27 15:00

Subject: [PATCH] imap-send: suppress warning about cleartext password with CRAM-MD5
Message-ID: <1269702019-27063-1-git-send-email-chris@arachsys.com>
URL: https://gitlist.dev/e/1269702019-27063-1-git-send-email-chris%40arachsys.com

```
If a CRAM-MD5 challenge-response is used to authenticate to the IMAP server,
git imap-send shouldn't warn about the password being sent in the clear.

Signed-off-by: Chris Webb <chris@arachsys.com>
---
 imap-send.c |    6 +++---
 1 files changed, 3 insertions(+), 3 deletions(-)

diff --git a/imap-send.c b/imap-send.c
index aeb2985..7107923 100644
--- a/imap-send.c
+++ b/imap-send.c
@@ -1226,9 +1226,6 @@ static struct store *imap_open_store(struct imap_server_conf *srvc)
 			fprintf(stderr, "Skipping account %s@%s, server forbids LOGIN\n", srvc->user, srvc->host);
 			goto bail;
 		}
-		if (!imap->buf.sock.ssl)
-			imap_warn("*** IMAP Warning *** Password is being "
-				  "sent in the clear\n");
 
 		if (srvc->auth_method) {
 			struct imap_cmd_cb cb;
@@ -1253,6 +1250,9 @@ static struct store *imap_open_store(struct imap_server_conf *srvc)
 				goto bail;
 			}
 		} else {
+			if (!imap->buf.sock.ssl)
+				imap_warn("*** IMAP Warning *** Password is being "
+					  "sent in the clear\n");
 			if (imap_exec(ctx, NULL, "LOGIN \"%s\" \"%s\"", srvc->user, srvc->pass) != RESP_OK) {
 				fprintf(stderr, "IMAP error: LOGIN failed\n");
 				goto bail;
-- 
1.7.0.1

```

## Junio C Hamano, 2010-03-28 16:25

Subject: Re: [PATCH] imap-send: suppress warning about cleartext password with CRAM-MD5
Message-ID: <7vbpe85s7n.fsf@alter.siamese.dyndns.org>
URL: https://gitlist.dev/e/7vbpe85s7n.fsf%40alter.siamese.dyndns.org
In-Reply-To: <1269702019-27063-1-git-send-email-chris@arachsys.com>

```
Chris Webb <chris@arachsys.com> writes:

> If a CRAM-MD5 challenge-response is used to authenticate to the IMAP server,
> git imap-send shouldn't warn about the password being sent in the clear.
>
> Signed-off-by: Chris Webb <chris@arachsys.com>
> ---

Makes sense.  Thanks.

>  imap-send.c |    6 +++---
>  1 files changed, 3 insertions(+), 3 deletions(-)
>
> diff --git a/imap-send.c b/imap-send.c
> index aeb2985..7107923 100644
> --- a/imap-send.c
> +++ b/imap-send.c
> @@ -1226,9 +1226,6 @@ static struct store *imap_open_store(struct imap_server_conf *srvc)
>  			fprintf(stderr, "Skipping account %s@%s, server forbids LOGIN\n", srvc->user, srvc->host);
>  			goto bail;
>  		}
> -		if (!imap->buf.sock.ssl)
> -			imap_warn("*** IMAP Warning *** Password is being "
> -				  "sent in the clear\n");
>  
>  		if (srvc->auth_method) {
>  			struct imap_cmd_cb cb;
> @@ -1253,6 +1250,9 @@ static struct store *imap_open_store(struct imap_server_conf *srvc)
>  				goto bail;
>  			}
>  		} else {
> +			if (!imap->buf.sock.ssl)
> +				imap_warn("*** IMAP Warning *** Password is being "
> +					  "sent in the clear\n");
>  			if (imap_exec(ctx, NULL, "LOGIN \"%s\" \"%s\"", srvc->user, srvc->pass) != RESP_OK) {
>  				fprintf(stderr, "IMAP error: LOGIN failed\n");
>  				goto bail;
> -- 
> 1.7.0.1

```

## Hitoshi Mitake, 2010-03-30 10:51

Subject: Re: [PATCH] imap-send: suppress warning about cleartext password with CRAM-MD5
Message-ID: <4BB1D7AC.80508@dcl.info.waseda.ac.jp>
URL: https://gitlist.dev/e/4BB1D7AC.80508%40dcl.info.waseda.ac.jp
In-Reply-To: <7vbpe85s7n.fsf@alter.siamese.dyndns.org>

```
On 03/29/10 01:25, Junio C Hamano wrote:
 > Chris Webb<chris@arachsys.com>  writes:
 >
 >> If a CRAM-MD5 challenge-response is used to authenticate to the IMAP 
server,
 >> git imap-send shouldn't warn about the password being sent in the clear.
 >>
 >> Signed-off-by: Chris Webb<chris@arachsys.com>
 >> ---
 >
 > Makes sense.  Thanks.
 >
 >>   imap-send.c |    6 +++---
 >>   1 files changed, 3 insertions(+), 3 deletions(-)
 >>
 >> diff --git a/imap-send.c b/imap-send.c
 >> index aeb2985..7107923 100644
 >> --- a/imap-send.c
 >> +++ b/imap-send.c
 >> @@ -1226,9 +1226,6 @@ static struct store *imap_open_store(struct 
imap_server_conf *srvc)
 >>   			fprintf(stderr, "Skipping account %s@%s, server forbids 
LOGIN\n", srvc->user, srvc->host);
 >>   			goto bail;
 >>   		}
 >> -		if (!imap->buf.sock.ssl)
 >> -			imap_warn("*** IMAP Warning *** Password is being "
 >> -				  "sent in the clear\n");
 >>
 >>   		if (srvc->auth_method) {
 >>   			struct imap_cmd_cb cb;
 >> @@ -1253,6 +1250,9 @@ static struct store *imap_open_store(struct 
imap_server_conf *srvc)
 >>   				goto bail;
 >>   			}
 >>   		} else {
 >> +			if (!imap->buf.sock.ssl)
 >> +				imap_warn("*** IMAP Warning *** Password is being "
 >> +					  "sent in the clear\n");
 >>   			if (imap_exec(ctx, NULL, "LOGIN \"%s\" \"%s\"", srvc->user, 
srvc->pass) != RESP_OK) {
 >>   				fprintf(stderr, "IMAP error: LOGIN failed\n");
 >>   				goto bail;
 >> --
 >> 1.7.0.1
 >

Thanks Chris, this was my mistake.
And thanks for your notify, Junio.

     Hitoshi

```
