Conversation

Jarkko Sakkinen

Edited 3 months ago

Have to add that I neither like the silly sec.conf in #weechat ;-) It sucks but is less worse than exposing passwords in plain text. I use weechat at least up until this has been fixed (if it ever will be). [the best possible solution would be obviously to have password command option like every other software]

I neither have motivation to add that option myself because it is quite obvious that it would be pain to get it landed based on comment that I responded to. I would only end up spending 1-2 nights writing code and 2 months collecting bad karma ;-)

1
0
0

@jarkko We accept PRs :) When we get an interesting PR we will work with the author to make it acceptable into core

1
0
1
@vague yeah so I get that encryption system in IRC client is something that no one wants to maintain. So that denial is from legit standing point.

However, having some to say that please run command instead of just reading password should not be tedious to maintain. Gives user a choice.

Problem implementing custom encryption storages is difficult and one can easily introduce a completely new set of security issues by doing that.

So I go through the official route but what I was thinking would be to add "-passcmd" to /connect.
1
0
1
@vague Just checking but is codeberg the main hosting site where the PR's are to be sent?
1
0
0

@jarkko github is the official repo but PRs can be sent to codeberg too

0
0
1