Mail: AUTH LOGIN für Exchange Online (504 5.7.4) #135

Open
thiel wants to merge 0 commits from mail-auth-login into main
Owner

Exchange Online bietet nach STARTTLS nur AUTH LOGIN XOAUTH2 an; SONE schickte fest AUTH PLAIN und bekam 504 5.7.4 Unrecognized authentication type. Der Client liest jetzt die EHLO-Capabilities und spricht LOGIN, wo es PLAIN nicht gibt. Fünf neue Tests gegen den Fake-Relay, drei davon rot gegen den alten Client. Passwort-Zeilen von AUTH LOGIN tauchen in Fehlermeldungen nicht auf.

Exchange Online bietet nach STARTTLS nur `AUTH LOGIN XOAUTH2` an; SONE schickte fest `AUTH PLAIN` und bekam `504 5.7.4 Unrecognized authentication type`. Der Client liest jetzt die EHLO-Capabilities und spricht LOGIN, wo es PLAIN nicht gibt. Fünf neue Tests gegen den Fake-Relay, drei davon rot gegen den alten Client. Passwort-Zeilen von AUTH LOGIN tauchen in Fehlermeldungen nicht auf.
The client reads which AUTH the relay offers, and speaks LOGIN where there is no PLAIN
All checks were successful
Test / test (pull_request) Successful in 4m9s
882a90f3c7
Exchange Online answers `AUTH PLAIN` with `504 5.7.4 Unrecognized authentication
type` because after STARTTLS it offers only `AUTH LOGIN XOAUTH2`. SONE sent
PLAIN regardless: the session kept only the last line of a reply, so the
capability lines of EHLO were never seen.

- `Session.reply()` returns every line of a reply, not just the last.
- `offeredAuth()` reads the AUTH line (RFC 4954 form and the `AUTH=` form).
- PLAIN when offered or when the relay says nothing, LOGIN when only that is,
  otherwise an error that names what the relay does offer.
- The credential lines of AUTH LOGIN are labelled `AUTH` in errors so a wrong
  password does not put its base64 on an administrator's screen.
- `sendMail` takes a `dial` so the fake relay in the tests can hear the AUTH
  step, which only ever happens over TLS and had never been tested.

Three of the new tests are red against the previous client.
thiel force-pushed mail-auth-login from 882a90f3c7
All checks were successful
Test / test (pull_request) Successful in 4m9s
to e6eb260450
All checks were successful
Test / test (pull_request) Successful in 4m6s
2026-09-22 22:41:04 +00:00
Compare
All checks were successful
Test / test (pull_request) Successful in 4m6s
This pull request has changes conflicting with the target branch.
  • .env.example
  • CHANGELOG.md
  • README.md
  • docker-compose.yml
  • docs/actions-runner.md
  • docs/adr/0173-two-brackets.md
  • docs/adr/0187-push-limits-and-an-honest-status.md
  • docs/deployment.md
  • docs/import-export.md
  • docs/releasing.md
  • package.json
  • packages/core/src/doc/blockTree.ts
  • packages/core/src/doc/docSchema.ts
  • packages/core/src/doc/migrations.ts
  • packages/core/test/searchQuery.test.ts
  • packages/editor/src/commands.ts
  • packages/editor/src/index.ts
  • packages/editor/src/inputRules.ts
  • packages/editor/src/mentionMenu.ts
  • packages/editor/src/pageLinkMenu.ts
  • packages/editor/src/schema.ts
  • packages/editor/test/blockLock.test.ts
  • packages/editor/test/homeRelative.test.ts
  • packages/editor/test/mentionMenu.test.ts
  • packages/server/src/export/build.ts
  • packages/server/src/export/markdown.ts
  • packages/server/src/http/pages.ts
  • packages/server/src/import/execute.ts
  • packages/server/src/import/markdown.ts
  • packages/server/src/import/plan.ts
  • packages/server/src/jobs/routes.ts
  • packages/server/src/materialize/materialize.ts
  • packages/server/test/api.db.test.ts
  • packages/server/test/importExecute.db.test.ts
  • packages/server/test/importMarkdown.test.ts
  • packages/web/src/api/client.ts
  • packages/web/src/components/BlockMenu.tsx
  • packages/web/src/components/EditorSurface.tsx
  • packages/web/src/components/FileNodeView.ts
  • packages/web/src/components/RightSidebar.tsx
  • packages/web/src/components/VideoNodeView.ts
  • packages/web/src/components/WorkspaceExport.tsx
  • packages/web/src/components/icons.tsx
  • packages/web/src/hooks/useDocAssets.ts
  • packages/web/src/i18n/messages.de.ts
  • packages/web/src/i18n/messages.en.ts
  • packages/web/src/routes/internalLinks.ts
  • packages/web/src/styles.css
  • packages/web/test/docAssets.test.ts
  • packages/web/test/editorSurface.test.tsx
  • packages/web/test/fileBlock.test.ts
  • packages/web/test/internalLinks.test.ts
  • packages/web/test/mentionDraft.test.ts
  • scripts/check-ci-tools.mjs
View command line instructions

Manual merge helper

Use this merge commit message when completing the merge manually.

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin mail-auth-login:mail-auth-login
git switch mail-auth-login

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff mail-auth-login
git switch mail-auth-login
git rebase main
git switch main
git merge --ff-only mail-auth-login
git switch mail-auth-login
git rebase main
git switch main
git merge --no-ff mail-auth-login
git switch main
git merge --squash mail-auth-login
git switch main
git merge --ff-only mail-auth-login
git switch main
git merge mail-auth-login
git push origin main
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
thiel/sone!135
No description provided.