nutrition docker file fix
This commit is contained in:
@@ -121,11 +121,34 @@ func (m *smtpMailer) dial() (*smtp.Client, error) {
|
||||
return nil, fmt.Errorf("could not reach the mail server at %s: %w", m.cfg.Address(), err)
|
||||
}
|
||||
|
||||
if ok, _ := client.Extension("STARTTLS"); ok {
|
||||
ok, _ := client.Extension("STARTTLS")
|
||||
if ok {
|
||||
if err := client.StartTLS(&tls.Config{ServerName: m.cfg.Host}); err != nil {
|
||||
client.Close()
|
||||
return nil, fmt.Errorf("the mail server offered TLS and then refused it: %w", err)
|
||||
}
|
||||
return client, nil
|
||||
}
|
||||
|
||||
// No TLS on offer, and we are about to send a password.
|
||||
//
|
||||
// Refused rather than continued. `smtp.PlainAuth` would decline to hand over
|
||||
// credentials on a plaintext connection anyway — so nothing leaks either way
|
||||
// — but it reports that as the server refusing our credentials, which sends
|
||||
// somebody to check the password when the problem is the connection.
|
||||
//
|
||||
// It also closes a downgrade: an attacker between us and the relay can strip
|
||||
// the STARTTLS advertisement from the greeting, and "carry on unencrypted"
|
||||
// is the wrong answer to that.
|
||||
//
|
||||
// A relay that authenticates by network rather than by credentials has no
|
||||
// username set, and is left alone: those are usually a local MTA on the same
|
||||
// host, where there is no wire to protect.
|
||||
if m.cfg.Username != "" {
|
||||
client.Close()
|
||||
return nil, fmt.Errorf(
|
||||
"%s does not offer TLS, and MAIL_PASSWORD would have to cross the wire in clear",
|
||||
m.cfg.Address())
|
||||
}
|
||||
return client, nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user