Re: bug#58985: 29.0.50; Have auth-source-pass behave more like other back ends

Akib Azmain Turja <[email protected]>
Newsgroups gmane.emacs.erc.general
Message-ID <[email protected]>
Michael Albinus <[email protected]> writes:

> "J.P." <[email protected]> writes:
>
> Hi,
>
>> v2. Respect existing user option.
>
> I'm not familiar with the auth-source-pass.el implementation, so I
> cannot speak too much about your patch. Reading it roughly, I haven't
> found serious flaws, 'tho.

It has a serious flaw AFAIK.  I have a password entry
"[email protected]", and this legitimate search query doesn't find it:

(auth-source-search :host "disroot.org")

But if specify the user, it finds the entry:

(auth-source-search :host "disroot.org" :user "akib")

And the entries can also be ambiguous.  For example, the entry at path
"foo.org/bar.net" might be interpreted as the password of bar.net, or
as the password of the user "bar.net" on "foo.org".  The current
implementation seems to interpret such entries unpredictably.

>
> However :-)
>
> +(defcustom auth-source-pass-standard-search nil
> +  "Whether to use more standardized search behavior.
> +When nil, the password-store backend works like it always has and
> +considers at most one `:user' search parameter and returns at
> +most one result.  With t, it tries to more faithfully mimic other
> +auth-source backends."
> +  :version "29.1"
> +  :type 'boolean)
>
> - The name of this user option as well as its docstring are focussed on
>   the current behavior. People won't know what "mimic other auth-source
>   backends" would mean. Please describe the effect w/o that comparison,
>   and pls give it a name based on its effect, and not "...-standard-search".

I agree.  This variable should be something like
"auth-source-pass-old-search" (or even "...-obsolete-search").  And the
default should be nil, because it fixes many bugs, and it's pointless to
disable the fixes by the default.

>
> - I'm missing the documentation in doc/misc/auth.texi and etc/NEWS.

What documentation?  Of this change or anything else?  I think we should
focus on the implement before writing documentation.

>
> Best regards, Michael.
>
>
>

-- 
Akib Azmain Turja, GPG key: 70018CE5819F17A3BBA666AFE74F0EFA922AE7F5
Fediverse: [email protected]
Codeberg: akib
emailselfdefense.fsf.org | "Nothing can be secure without encryption."
signature.asc (application/pgp-signature, 832 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEyVTKmrtL6kNBe3FRVTX89U2IYWsFAmNr75cACgkQVTX89U2I
YWtZAhAA2023wqxFSfifBQ3Z321ua/gZyM0vR9hY5V9h/Z9RO4m1+JxpbF/yJ56a
V4pCfiN1b+q/YflO5r+k2EeMjxIYwBrFt6A2GI3LBMO43GIffaour0sv94EtGSU9
kh3fYS+9J9uLjCqupm4058PHBFHkUtbu9r3P4lwKPzxbXDbasb8my3+Jc/BcePhj
pgI0DbS88LiLLjZzN0C1kYsfF6r+ay6Jh4EN0k6VAG4EeSAlh/w6iUmonbX5J2sR
lIvUU910jMj+uImUmvpHpvy1KlpYT6OCT3R+PfqA0e4KGQMLJGcDTill8XTvxi2u
iVkWiGDffspPfE6I6FnHd1kqFUGe+zv3vKvy94wzyRfz9ymzugZWOJYflGsLFRxK
NKhhXUjBFfdEA7Fo8+T78c/VmOCaNPpjtUqAidfrtsdDUF8fQ93FU1CqWDsUXm+K
jjxUVaKP8z+xvv2f+KTlTCzP2T0THEwghlZQR02Dtmuq0uXPnbwrwjplkrIKSyTe
euak4q4RLEVn196clLqjJwcbHZjGSGJEaMtjYwFZ4kiwoxU3VyYez0sz7cWitK5N
TcTDplhQ3hoHXbmviJIBoTPqGLH38gt9FmfKlQ8JXwQ0XNWtMoHKfyI4fkLUMQ0n
tNLk9Y/sWWZlNgJydZXinOE+XCbCKiA95ysds0nUvHR6BImHJlA=
=HYbU
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.