nutrition docker file fix

This commit is contained in:
2026-09-30 14:58:30 +05:30
parent c49f5372a5
commit d0804ae84f
8 changed files with 430 additions and 112 deletions

View File

@@ -121,11 +121,34 @@ func (m *smtpMailer) dial() (*smtp.Client, error) {
return nil, fmt.Errorf("could not reach the mail server at %s: %w", m.cfg.Address(), err)
}
if ok, _ := client.Extension("STARTTLS"); ok {
ok, _ := client.Extension("STARTTLS")
if ok {
if err := client.StartTLS(&tls.Config{ServerName: m.cfg.Host}); err != nil {
client.Close()
return nil, fmt.Errorf("the mail server offered TLS and then refused it: %w", err)
}
return client, nil
}
// No TLS on offer, and we are about to send a password.
//
// Refused rather than continued. `smtp.PlainAuth` would decline to hand over
// credentials on a plaintext connection anyway — so nothing leaks either way
// — but it reports that as the server refusing our credentials, which sends
// somebody to check the password when the problem is the connection.
//
// It also closes a downgrade: an attacker between us and the relay can strip
// the STARTTLS advertisement from the greeting, and "carry on unencrypted"
// is the wrong answer to that.
//
// A relay that authenticates by network rather than by credentials has no
// username set, and is left alone: those are usually a local MTA on the same
// host, where there is no wire to protect.
if m.cfg.Username != "" {
client.Close()
return nil, fmt.Errorf(
"%s does not offer TLS, and MAIL_PASSWORD would have to cross the wire in clear",
m.cfg.Address())
}
return client, nil
}