feat: move doveauth from dictproxy to lua/http as recommended by dovecot 2.4 - #1049
Conversation
missytake
left a comment
There was a problem hiding this comment.
Looks good! This already works with dovecot 2.3? looking forward to trying it out tomorrow.
lua isn't that bad it seems, I can read most of it. Hope the parts of the syntax which are not super intuitive don't contain surprises.
| -- Entry points called by dovecot | ||
|
|
||
| function script_init() | ||
| http_client = dovecot.http.client({timeout = 5000, max_attempts = 1}) |
There was a problem hiding this comment.
Why is the timeout so high?
There was a problem hiding this comment.
glad you asked!
a) it's milliseconds
b) the dovecot 2.3 documentation and the dovecot 2.3.21 source code somewhat disagree about the name, it is request_timeout_msecs and i fixed it here. The docs have the function signature wrong.
There was a problem hiding this comment.
ah, good to know :D so that's the kind of thing you need to watch out for with lua?^^
There was a problem hiding this comment.
yes. I could have noticed because the docs when they describe the args use request_timeout_msecs. Usually dovecot docs are high quality. Only the function signature name was wrong.
| if not create(req.user, password) then | ||
| return dovecot.auth.PASSDB_RESULT_USER_UNKNOWN, {} | ||
| end | ||
| elseif req:password_verify(hash, password) ~= 1 then |
There was a problem hiding this comment.
is req:password_verify() a built-in lua function in dovecot? Or where is it implemented?
There was a problem hiding this comment.
Ah, if I understand it correctly, doveauth encrypts the password during create, dovecot verifies the password during lookup, and doveauth verifies the password only in rare cases when a user was accidentally created already while create/ is called? Just asking again to verify.
There was a problem hiding this comment.
yes, that's exactly how it goes. Dovecot has a builtin function to verify passwords, so logging in with existing accounts usually does not touch doveauth.py. But due to SMTP/IMAP logins being potentially concurrent, we need to have the python side also verify if it detects concurrency. Should be a rare happening, and doesn't matter as both sides agree on how to verify passwords.
f228589 to
c5d7867
Compare
|
Deployed on nine successfully. |
1. existing logins are now verified by lua only 2. non-existing logins are delegated to the new Python doveauth http /create endpoint Using Lua and http this way makes doveauth more compatible to dovecot 2.4
on doveauth.py being down, users would "AUTHENTIFICATIONFAILED"
while they now get:
IMAP failed to login as tovnlbmsz@_lua0.localchat: no response:
code: None, info: Some("[UNAVAILABLE] Temporary authentication
failure. [lua0-localchat:2026-09-01 11:00:17]")
59b96c4 to
d2b5f7b
Compare
dovecot 2.4 is dropping userdb/passdb lookups via dictproxy, and recommends lua
This PR moves password verification to lua, and keeps creating addresses in python via a http request, so that
doveauth.pykeeps owning the creation checks, and nothing changes there.The new auth.lua code is extensively tested and deploying it to an existing relay host works fine for me, and passes all tests.