Re: [Patch/Fix] libsecret configure option

Peter Bloomfield <[email protected]> Fri, 06 Mar 2020 17:41:10 -0500
Newsgroups gmane.comp.gnome.apps.balsa
Message-ID <[email protected]>
Hi Albrecht:

On 03/02/2020 04:12:23 PM Mon, Albrecht Dreß wrote:
> Hi all,
> 
> the configure option
> 
> <snip>
>   --with-libsecret        Link to libsecret instead of gnome-keyring
>                           (default=no)
> </snip>
> 
> is actually *wrong*, as gnome-keyring has been deprecated.  Thus, if a user follows this comment only (the README is actually correct), the resulting binary will store obfuscated passwords in ~/.balsa/config-private which is typically a questionable (at best) idea.
> 
> I suggest
> - to make using libsecret the default and
> - print a warning if the user explicitly wants to disable it.
> 
> The attached patch (untested for Meson) fixes the confusion.
> 
> We might also want to ensure that the password (or all passwords) is erased from config-private (see the comment in libbalsa/server.c, line 359ff.) when accessing libsecret was successful.
> 
> Opinions?
> 
> Best,
> Albrecht.

Thanks for the patch--looks good to me!

Feel free to commit.

Peter

_______________________________________________
balsa-list mailing list
[email protected]
https://mail.gnome.org/mailman/listinfo/balsa-list
signature.asc (application/pgp-signature, 195 B)
-----BEGIN PGP SIGNATURE-----

iF0EABECAB0WIQS030wPRfNNA5alz3MfX9S1uSp09QUCXmLRhgAKCRAfX9S1uSp0
9Xn3AKCN7l5Yh+zvc2ZbPJLy652YJeXPwwCfV8wXvFqzgvnWPP5WKroKewpAH9o=
=OBp0
-----END PGP SIGNATURE-----