Re: Bug in Digest authentication: Request with digest authentication fails if nonce is expired / GIT pull request #40
[email protected] (Mark Allen) Fri, 16 Aug 2013 09:31:00 -0700 (PDT)
| Newsgroups | perl.libwww |
|---|---|
| Message-ID | <[email protected]> |
--357420756-1442752355-1376670660=:56867 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable I know it can be frustrating to wait on an open PR, I've been there, done t= hat.=0A=0AThese are the people who can merge your PR=0A=0Ahttps://github.co= m/libwww-perl?tab=3Dmembers=0A=0A=0AIt looks like Gisle Aas, Matt Trout and= Karen Etheridge have permission on PAUSE to release a new=0Adistribution.= =0A=0AIt might be worthwhile to gently nudge one of these people in IRC via= =A0irc.perl.org=A0=0A=0AIn the meantime, it sounds like you've patched the = problem on your own fork. Using a tool like=0APinto, Stratopan or Carton yo= u could deploy your fork into your environment if you can't wait.=0A=0AWhet= her that is a Good Idea or Terribly Impractical depends on a lot of factors= unrelated to=A0=0Agetting your PR merged.=0A=0ACheers,=0A=0AMark=0A=0A=0A_= _______________________________=0A From: stefan lauterbach <[email protected]>=0ATo= : [email protected] =0ASent: Friday, August 16, 2013 5:19 AM=0ASubject: Bug i= n Digest authentication: Request with digest authentication fails if nonce = is expired / GIT pull request #40=0A =0A=0AHello,=0A=0AWhen I used digest a= uthentication in libwww, I came across the issue =0Athat the nonce expiry i= s not handled correctly, as described in issue =0A#39 on github (by me). I = also found an existing bug report on rt, which =0Adescribes the problem eve= n better: =0Ahttps://rt.cpan.org/Public/Bug/Display.html?id=3D75908.=0A=0AI= spent a lot of time to understand the module structure and fixed the =0Ais= sue, I also created tests for it (fixing also some other tests that =0Awere= non-operational), and I created pull request #40.=0A=0AI have not received= any response since. As also several other pull =0Arequests are unanswered,= the module looks quite unmaintained.=0A=0APlease have a look at this, I re= ally do not want to bother anyone, but =0Ait is a real problem in a subcase= of a central perl library, the fix is =0Aalready provided.=0A=0AI am also = ready to give more details and to improve my solution, if you =0Afind any i= ssues with it. However, I would not like to see my efforts =0Awasted. Pleas= e advise me how to proceed.=0A=0AThank you. --357420756-1442752355-1376670660=:56867 Content-Type: text/html; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable <html><body><div style=3D"color:#000; background-color:#fff; font-family:ve= rdana, helvetica, sans-serif;font-size:10pt"><div><span><font size=3D"2">I = know it can be frustrating to wait on an open PR, I've been there, done tha= t.</font></span></div><div style=3D"color: rgb(0, 0, 0); font-size: 13px; f= ont-family: verdana, helvetica, sans-serif; background-color: transparent; = font-style: normal;"><span><font size=3D"2"><br></font></span></div><div st= yle=3D"color: rgb(0, 0, 0); font-size: 13px; font-family: verdana, helvetic= a, sans-serif; background-color: transparent; font-style: normal;"><span><f= ont size=3D"2">These are the people who can merge your PR</font></span></di= v><div style=3D"color: rgb(0, 0, 0); font-size: 13px; font-family: verdana,= helvetica, sans-serif; background-color: transparent; font-style: normal;"= ><span><font size=3D"2"><br></font></span></div><div style=3D"color: rgb(0,= 0, 0); font-size: 13px; font-family: verdana, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span><font size=3D"2"= >https://github.com/libwww-perl?tab=3Dmembers</font><br></span></div><div s= tyle=3D"font-family: verdana, helvetica, sans-serif; font-size: 10pt;"><br>= </div><div style=3D"font-family: verdana, helvetica, sans-serif; font-size:= 13px; color: rgb(0, 0, 0); background-color: transparent; font-style: norm= al;">It looks like Gisle Aas, Matt Trout and Karen Etheridge have permissio= n on PAUSE to release a new</div><div style=3D"font-family: verdana, helvet= ica, sans-serif; font-size: 13px; color: rgb(0, 0, 0); background-color: tr= ansparent; font-style: normal;">distribution.</div><div style=3D"font-famil= y: verdana, helvetica, sans-serif; font-size: 13px; color: rgb(0, 0, 0); ba= ckground-color: transparent; font-style: normal;"><br></div><div style=3D"f= ont-family: verdana, helvetica, sans-serif; font-size: 13px; color: rgb(0, = 0, 0); background-color: transparent; font-style: normal;">It might be wort= hwhile to gently nudge one of these people in IRC via <span style=3D"backgro= und-color: transparent;">irc.perl.org </span></div><div style=3D"font-= family: verdana, helvetica, sans-serif; font-size: 13px; color: rgb(0, 0, 0= ); background-color: transparent; font-style: normal;"><br></div><div style= =3D"font-family: verdana, helvetica, sans-serif; font-size: 13px; color: rg= b(0, 0, 0); background-color: transparent; font-style: normal;">In the mean= time, it sounds like you've patched the problem on your own fork. Using a t= ool like</div><div style=3D"font-family: verdana, helvetica, sans-serif; fo= nt-size: 13px; color: rgb(0, 0, 0); background-color: transparent; font-sty= le: normal;">Pinto, Stratopan or Carton you could deploy your fork into you= r environment if you can't wait.</div><div style=3D"font-family: verdana, h= elvetica, sans-serif; font-size: 13px; color: rgb(0, 0, 0); background-colo= r: transparent; font-style: normal;"><br></div><div style=3D"font-family: verdana, helvetica, sans-serif; font-size: 13px; color: rgb(0, 0, 0); back= ground-color: transparent; font-style: normal;">Whether that is a Good Idea= or Terribly Impractical depends on a lot of factors unrelated to </di= v><div style=3D"font-family: verdana, helvetica, sans-serif; font-size: 13p= x; color: rgb(0, 0, 0); background-color: transparent; font-style: normal;"= >getting your PR merged.</div><div style=3D"font-family: verdana, helvetica= , sans-serif; font-size: 13px; color: rgb(0, 0, 0); background-color: trans= parent; font-style: normal;"><br></div><div style=3D"font-family: verdana, = helvetica, sans-serif; font-size: 13px; color: rgb(0, 0, 0); background-col= or: transparent; font-style: normal;">Cheers,</div><div style=3D"font-famil= y: verdana, helvetica, sans-serif; font-size: 13px; color: rgb(0, 0, 0); ba= ckground-color: transparent; font-style: normal;"><br></div><div style=3D"f= ont-family: verdana, helvetica, sans-serif; font-size: 13px; color: rgb(0, = 0, 0); background-color: transparent; font-style: normal;">Mark</div><div sty= le=3D"font-family: verdana, helvetica, sans-serif; font-size: 13px; color: = rgb(0, 0, 0); background-color: transparent; font-style: normal;"><br></div= > <div style=3D"font-family: verdana, helvetica, sans-serif; font-size: 10= pt;"> <div style=3D"font-family: 'times new roman', 'new york', times, seri= f; font-size: 12pt;"> <div dir=3D"ltr"> <hr size=3D"1"> <font size=3D"2" f= ace=3D"Arial"> <b><span style=3D"font-weight:bold;">From:</span></b> stefan= lauterbach <[email protected]><br> <b><span style=3D"font-weight: bold;">To:= </span></b> [email protected] <br> <b><span style=3D"font-weight: bold;">Sent= :</span></b> Friday, August 16, 2013 5:19 AM<br> <b><span style=3D"font-wei= ght: bold;">Subject:</span></b> Bug in Digest authentication: Request with = digest authentication fails if nonce is expired / GIT pull request #40<br> = </font> </div> <div class=3D"y_msg_container"><br>Hello,<br><br>When I used= digest authentication in libwww, I came across the issue <br>that the nonce expir= y is not handled correctly, as described in issue <br>#39 on github (by me)= . I also found an existing bug report on rt, which <br>describes the proble= m even better: <br>https://rt.cpan.org/Public/Bug/Display.html?id=3D75908.<= br><br>I spent a lot of time to understand the module structure and fixed t= he <br>issue, I also created tests for it (fixing also some other tests tha= t <br>were non-operational), and I created pull request #40.<br><br>I have = not received any response since. As also several other pull <br>requests ar= e unanswered, the module looks quite unmaintained.<br><br>Please have a loo= k at this, I really do not want to bother anyone, but <br>it is a real prob= lem in a subcase of a central perl library, the fix is <br>already provided= .<br><br>I am also ready to give more details and to improve my solution, i= f you <br>find any issues with it. However, I would not like to see my efforts <br>wasted. Please advise me how to proceed.<br><br>Thank you.<br>= <br><br><br><br></div> </div> </div> </div></body></html> --357420756-1442752355-1376670660=:56867--