Skip to content

Use a safe implementation of SCRAM. #914

@mberhault

Description

@mberhault

The scram implementation has no unittests and ignores parts of the RFC (eg: the m field is supposed to trigger an authentication failure). This should be replaced with a fuller (and better tested) implementation. https://github.com/xdg-go/scram might be a candidate.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions