Re: [Imap-protocol] Gmail - OAUTH2 - failures since Feb 23

Gilles LAMIRAL <[email protected]> Wed, 8 Mar 2017 20:01:21 +0100
Newsgroups gmane.mail.imap.general
Message-ID <[email protected]>
Hi all,

Isn't it the last Apache patch that now disallow "broken" (not strict RFC72=
30  compliant)
http clients that still use \n instead of \r\n as end of lines?

Using only \n now generates an Apache (2.2) 400 HTTP error, it looks like s=
ome
sort of error code mapping with what described Kostya Vasilyev:
"using this token to log into Gmail would get "status code 400,
bad request" from Gmail's IMAP and SMTP servers."

I saw this happening in Debian last apache 2.2 patch:
https://tracker.debian.org/news/839792
* Security: CVE-2016-8743:
      Enforce HTTP request grammar corresponding to RFC7230 for request lin=
es
      and request headers, to prevent response splitting and cache pollutio=
n by
      malicious clients or downstream proxies.
* The stricter HTTP enforcement may cause compatibility problems with
      non-conforming clients. Fine-tuning is possible with the new
      HttpProtocolOptions directive.

It's not strictly imap related but it shows again that http is almost every=
where now.

Le 24/02/2017 =E0 17:55, Brandon Long a =E9crit :
> https://twitter.com/Google/status/834993667911737345
>
> We had some issues with account login yesterday for oauth, it should all =
be resolved now.
>

-- =

Au revoir,
Gilles Lamiral. France, Baulon (35580)
mob 06 19 22 03 54
tel 09 51 84 42 42
_______________________________________________
Imap-protocol mailing list
[email protected]
http://mailman13.u.washington.edu/mailman/listinfo/imap-protocol