[dovecot/core] 52fe79: imap-login: If LOGINDISABLED capability is adverti...
GitHub
noreply at github.com
Tue Jan 19 21:49:06 UTC 2016
Branch: refs/heads/master
Home: https://github.com/dovecot/core
Commit: 52fe791133ad838c3aca3f1c88f96aab755950f8
https://github.com/dovecot/core/commit/52fe791133ad838c3aca3f1c88f96aab755950f8
Author: Timo Sirainen <timo.sirainen at dovecot.fi>
Date: 2016-01-19 (Tue, 19 Jan 2016)
Changed paths:
M src/imap-login/imap-login-client.h
M src/imap-login/imap-proxy.c
Log Message:
-----------
imap-login: If LOGINDISABLED capability is advertised in banner, don't try to LOGIN without SSL/TLS.
This avoids accidentally sending the password in plaintext. Also the server
should fail the LOGIN in any case.
More information about the dovecot-cvs
mailing list