[PR #2937] Authentication is only applied when both the username and password have values. #23920

Closed
opened 2026-02-21 20:22:01 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/2937

State: closed
Merged: Yes


Description

no auth in smtp is implemented in https://github.com/langgenius/dify/pull/2765 , but there's a bug, SMTP.sendmail requires the first sender address as the first argument.

When username is set to none, the auth is skipped but sendmail would fail due to the type error

When username is set to empty string, the auth is skipped , mail was sent, but this mail envelope does not include sender info, which could lead to rejection by server.

So the correct configuration for no-auth smtp would be

SMTP_USERNAME=no-reply@example.com
SMTP_PASSWORD="" # or just dont set

In the current logic, if a username is provided, authentication will be performed, which is not as expected. Therefore, the logic of authentication at this point needs to be modified from authenticating when a username is present to authenticating only when both username and password are provided.

Type of Change

Please delete options that are not relevant.

  • Bug fix (non-breaking change which fixes an issue)

How Has This Been Tested?

Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration

  • import SMPTClient and try to send a mail
>>> from smtp import SMTPClient
>>> c = SMTPClient("mail.example.com", 25, "no-reply@example.com", "", "no-reply@example.com")
>>> c.send({"subject": "test", "to": "my-box@example.com", "html": "<p>hello</p>"})

And I can receive the mail.

Suggested Checklist:

  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • My changes generate no new warnings
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
  • optional I have made corresponding changes to the documentation
  • optional I have added tests that prove my fix is effective or that my feature works
  • optional New and existing unit tests pass locally with my changes
**Original Pull Request:** https://github.com/langgenius/dify/pull/2937 **State:** closed **Merged:** Yes --- # Description `no auth` in smtp is implemented in https://github.com/langgenius/dify/pull/2765 , but there's a bug, [SMTP.sendmail](https://docs.python.org/3/library/smtplib.html#smtplib.SMTP.sendmail) requires the first sender address as the first argument. When username is set to none, the auth is skipped but `sendmail` would fail due to the type error When username is set to empty string, the auth is skipped , mail was sent, but this mail envelope does not include sender info, which could lead to rejection by server. So the correct configuration for `no-auth` smtp would be ``` SMTP_USERNAME=no-reply@example.com SMTP_PASSWORD="" # or just dont set ``` In the current logic, if a username is provided, authentication will be performed, which is not as expected. Therefore, the logic of authentication at this point needs to be modified from authenticating when a username is present to authenticating only when both username and password are provided. ## Type of Change Please delete options that are not relevant. - [x] Bug fix (non-breaking change which fixes an issue) # How Has This Been Tested? Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration - [x] import SMPTClient and try to send a mail ``` >>> from smtp import SMTPClient >>> c = SMTPClient("mail.example.com", 25, "no-reply@example.com", "", "no-reply@example.com") >>> c.send({"subject": "test", "to": "my-box@example.com", "html": "<p>hello</p>"}) ``` And I can receive the mail. # Suggested Checklist: - [x] I have performed a self-review of my own code - [x] I have commented my code, particularly in hard-to-understand areas - [x] My changes generate no new warnings - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods - [ ] `optional` I have made corresponding changes to the documentation - [ ] `optional` I have added tests that prove my fix is effective or that my feature works - [x] `optional` New and existing unit tests pass locally with my changes
yindo added the pull-request label 2026-02-21 20:22:01 -05:00
yindo closed this issue 2026-02-21 20:22:01 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#23920