Uh oh!
There was an error while loading. Please reload this page.
Do not load deprecated SASL mechanisms by default - #58
Conversation
nevans
commented
Feb 22, 2022
The list of non-deprecated SASL mechanisms is down to only |
| spec.add_development_dependency "digest" | ||
| spec.add_development_dependency "strscan" |
There was a problem hiding this comment.
I'm not entirely sure how gem dev deps are treated by Bundler, but I guess they are ignored if e.g. a app Gemfile depends on mail or net-imap?
There was a problem hiding this comment.
They are ignored with bundle install by default.
nevans
commented
Jul 14, 2022
👍 I've been sitting on code for a couple of new SASL mechanisms, and a bugfix for "DIGEST-MD5" (when |
Mark obolete SASL mechanisms as deprecated (fixesrubyGH-55): * Warn every time a deprecated mechanism is used. * Warnings can be disabled with `warn_deprecation: false` * delay loading stdgem dependencies until `#initialize`. FixesrubyGH-56. * This is a backwards-compatible alternative to the approach in rubyGH-58 (don't require and add the deprecated authenticators automatically). We can use that incompatible approach in a later version. Additionally: * Adds basic tests for every authenticator (to avoid another rubyGH-52!) * Fixes a frozen string bug in DigestMD5Authenticator. * By making these optional, there's no reason to require the `digest` or `strscan` gems anymore; fixesrubyGH-56. The DIGEST-MD5 bug was originally reported, tested, and fixed by @singpolyma here: nevans/net-sasl#3. Co-authored-by: Stephen Paul Weber <singpolyma@singpolyma.net>
Mark obolete SASL mechanisms as deprecated (fixesGH-55): * This is a backwards-compatible alternative to the approach in GH-58 (don't require and add the deprecated authenticators automatically). We can use that incompatible approach in a later version. * Warn every time a deprecated mechanism is used. * Warnings can be disabled with `warn_deprecation: false` * delay loading stdgem dependencies until `#initialize`. FixesGH-56. Additionally: * Adds basic tests for every authenticator (to avoid another GH-52!) * Fixes a frozen string bug in DigestMD5Authenticator. * By making these optional, there's no reason to require the `digest` or `strscan` gems anymore; fixesGH-56. The DIGEST-MD5 bug was originally reported, tested, and fixed by @singpolyma here: nevans/net-sasl#3. Co-authored-by: Stephen Paul Weber <singpolyma@singpolyma.net>
Mark obolete SASL mechanisms as deprecated (fixesGH-55): * This is a backwards-compatible alternative to the approach in GH-58 (don't require and add the deprecated authenticators automatically). We can use that incompatible approach in a later version. * Warn every time a deprecated mechanism is used. * Warnings can be disabled with `warn_deprecation: false` * FixesGH-56: delay loading standard gem dependencies until `#initialize`, and convert the gems to development dependencies. Additionally: * Adds basic tests for every authenticator (to avoid another GH-52!) * Fixes a frozen string bug in DigestMD5Authenticator. * Fixes constant resolution for exceptions in DigestMD5Authenticator. * Can register an authenticator type that responds to #call (instead of #new). I was originally going to register deprecated authenticators with a Proc that required the file and issued a warning, but I decided to put everything into the initializer instead. `#authenticator` needed to be updated to safely delegate all args, and I left this in. The DIGEST-MD5 bug was originally reported, tested, and fixed by @singpolyma here: nevans/net-sasl#3. Co-authored-by: Stephen Paul Weber <singpolyma@singpolyma.net>
nevans
commented
Jul 16, 2022
I remembered why I hadn't pushed a PR for that other SASL code yet. My refactorings went a little bit further than I wanted for a ticket like this, and I wasn't quite done yet! But I might have that one ready for review soon, too. At any rate, that branch reminded me that I wanted to try a different backward-compatible approach. That approach and the DIGEST-MD5 bugfixes are here: If you think that approach is okay, let's close this ticket and merge that one instead. |
n.b. the mechanisms haven't been removed. They just aren't loaded by
default. ClosesGH-55.
By making these optional, there's no reason to require the
digestorstrscangems anymore. ClosesGH-56.