[tpop3d-discuss] whoson protocol

Chris Lightfoot chris at ex-parrot.com
Fri, 28 Jun 2002 15:04:35 +0100


On Fri, Jun 28, 2002 at 01:00:33PM +0100, Chris Elsworth wrote:
> On Thu, Jun 27, 2002 at 09:36:27PM +0100, Chris Lightfoot wrote:
    [...]
> > Does this really work? I thought that typical MUAs such as
> > Microsoft Outlook Express sent mail after checking mail,
> > rather than simultaneously. Or is the intention that POP3
> > servers don't issue LOGOUT commands?
> 
> I thought the whoson session was valid for about 10 minutes after the
> POP3 LOGOUT signal. The whoson daemon monitors the valid sessions and
> expires them after 10 minutes.

Ah, OK, that makes sense.

> > This would be pretty easy to implement-- conceptually it's
> > very much like the DRAC stuff which is already in there,
> > especially since the WHOSON people supply a library. I'll
> > put it on the TODO list; perhaps[1] somebody would like
> > to send me a patch against 1.4.2.
> 
> I would actually quite like to get a bit more involved in a nice
> project like this one, but first of all I need to understand how the
> entire existing codebase works, and by the time I've done that someone
> will have done the patch :) I'll make it a point one day soon to walk
> through the code and figure out how it all works.

Please do. Then you can tell me about all the bugs you
find, so that I can fix them. Or better, you could fix
them and send me a patch :)

(Seriously, `real security audit' is on the to do list and
has been for a long time. The problem is that security
auditing is both non-trivial and boring....)


-- 
``Intelligence has much less practical application than you'd think.''
  (Scott Adams, from `Dilbert')