[dovecot/core] 52fe79: imap-login: If LOGINDISABLED capability is adverti...

GitHub noreply at github.com
Tue Jan 19 21:49:06 UTC 2016


  Branch: refs/heads/master
  Home:   https://github.com/dovecot/core
  Commit: 52fe791133ad838c3aca3f1c88f96aab755950f8
      https://github.com/dovecot/core/commit/52fe791133ad838c3aca3f1c88f96aab755950f8
  Author: Timo Sirainen <timo.sirainen at dovecot.fi>
  Date:   2016-01-19 (Tue, 19 Jan 2016)

  Changed paths:
    M src/imap-login/imap-login-client.h
    M src/imap-login/imap-proxy.c

  Log Message:
  -----------
  imap-login: If LOGINDISABLED capability is advertised in banner, don't try to LOGIN without SSL/TLS.

This avoids accidentally sending the password in plaintext. Also the server
should fail the LOGIN in any case.




More information about the dovecot-cvs mailing list