Fix permissions handling (CVE-2010-0825).
[emacs.git] / lisp / net / sasl-cram.el
blob9faeded5c3bbd2a27a8749b96633615d329e0fe5
1 ;;; sasl-cram.el --- CRAM-MD5 module for the SASL client framework
3 ;; Copyright (C) 2000, 2007, 2008, 2009, 2010 Free Software Foundation, Inc.
5 ;; Author: Daiki Ueno <ueno@unixuser.org>
6 ;; Kenichi OKADA <okada@opaopa.org>
7 ;; Keywords: SASL, CRAM-MD5
9 ;; This file is part of GNU Emacs.
11 ;; GNU Emacs is free software: you can redistribute it and/or modify
12 ;; it under the terms of the GNU General Public License as published by
13 ;; the Free Software Foundation, either version 3 of the License, or
14 ;; (at your option) any later version.
16 ;; GNU Emacs is distributed in the hope that it will be useful,
17 ;; but WITHOUT ANY WARRANTY; without even the implied warranty of
18 ;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 ;; GNU General Public License for more details.
21 ;; You should have received a copy of the GNU General Public License
22 ;; along with GNU Emacs. If not, see <http://www.gnu.org/licenses/>.
24 ;;; Commentary:
26 (require 'sasl)
27 (require 'hmac-md5)
29 (defconst sasl-cram-md5-steps
30 '(ignore ;no initial response
31 sasl-cram-md5-response))
33 (defun sasl-cram-md5-response (client step)
34 (let ((passphrase
35 (sasl-read-passphrase
36 (format "CRAM-MD5 passphrase for %s: "
37 (sasl-client-name client)))))
38 (unwind-protect
39 (concat (sasl-client-name client) " "
40 (encode-hex-string
41 (hmac-md5 (sasl-step-data step) passphrase)))
42 (fillarray passphrase 0))))
44 (put 'sasl-cram 'sasl-mechanism
45 (sasl-make-mechanism "CRAM-MD5" sasl-cram-md5-steps))
47 (provide 'sasl-cram)
49 ;; arch-tag: 46cb281b-975a-4fe0-a39f-3018691b1b05
50 ;;; sasl-cram.el ends here