From 46275eef3de4e025b5657e67e142fc58125779be Mon Sep 17 00:00:00 2001 From: Simeon Simeonov Date: Fri, 13 Apr 2018 15:24:01 +0200 Subject: Add support for auto-unloading av the master password --- src/prefs_ui.c | 19 ++++++++++++++++++- 1 file changed, 18 insertions(+), 1 deletion(-) (limited to 'src/prefs_ui.c') diff --git a/src/prefs_ui.c b/src/prefs_ui.c index 5539f4a..051a058 100644 --- a/src/prefs_ui.c +++ b/src/prefs_ui.c @@ -31,6 +31,7 @@ #include #include "prefs.h" +#include "prefs_common.h" #include "prefs_ui.h" #include "menu.h" #include "codeconv.h" @@ -276,9 +277,25 @@ void prefs_set_data_from_epass_entry(PrefParam *pparam) gchar **str; const gchar *entry_str; - if (!master_password_active()) { + /* This is where decrypted passwords are encrypted and stored again */ + + /* TODO: A potential exploit is disabling master password and then forcing + * Sylpheed to store the password + */ + + /* master_password == NULL for any of the following reasons: + * - use_master_password is not enabled (we just save without encrypting) + * - master_password is auto unloaded (let the encrypt function handle it) + * - undefined reason (refure to store the password) + */ + if (!prefs_common.use_master_password) { prefs_set_data_from_entry(pparam); return; + } else if ((master_password == NULL) && + (!prefs_common.auto_unload_master_password)) { + debug_print("Master password enabled, but not loaded for no " + "apparent reason. Not storing\n"); + return; } ui_data = (PrefsUIData *)pparam->ui_data; -- cgit v1.3