Skip to content

Commit b3a4a2c

Browse files
authored
starttls: Clear unencrypted commands from buffer (#380)
1 parent 6e148d7 commit b3a4a2c

2 files changed

Lines changed: 7 additions & 0 deletions

File tree

aiosmtpd/docs/NEWS.rst

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,10 @@
44

55
.. towncrier release notes start
66
7+
1.4.6 (2024-05-06)
8+
==================
9+
10+
* STARTTLS is now fully enforced if used.
711

812
1.4.5 (2024-03-02)
913
==================

aiosmtpd/smtp.py

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -504,6 +504,9 @@ def connection_made(self, transport: asyncio.BaseTransport) -> None:
504504
self._reader._transport = transport # type: ignore[attr-defined]
505505
self._writer._transport = transport # type: ignore[attr-defined]
506506
self.transport = transport
507+
# Discard any leftover unencrypted data
508+
# See https://tools.ietf.org/html/rfc3207#page-7
509+
self._reader._buffer.clear() # type: ignore[attr-defined]
507510
# Do SSL certificate checking as rfc3207 part 4.1 says. Why is
508511
# _extra a protected attribute?
509512
assert self._tls_protocol is not None

0 commit comments

Comments
 (0)