Package: liferea
Version: 1.8.6-1.1
Severity: important

Dear Maintainer,

Liferea is repeatedly asking for HTTP Basic Auth credentials on feeds
with stored credentials, although the first update for each feed
succeeds. I think this is due to trying to re-use a nonce.

Here is an example feed; a free Livejournal account's credentials are
sufficient for login. davis-square community membership is not
required:

http://davis-square.livejournal.com/data/rss?auth=digest

When Liferea is first launched, these feeds authenticate
successfully. Wireshark shows that each initial response is a 401, and
that Liferea then correctly re-sends with an Authorization: Digest
header using the nonce and algorithm requested. However, subsequent
updates to the feed simply send the same Authorization: Digest line as
before, with the same nonce. The feed server responds with a 401 and a
different nonce, and Liferea gives up and prompts for username and
password (sometimes blank, sometimes pre-filled -- different bug, or a
consequence of this one?)  Entering or accepting the credentials
allows the update to proceed.

The consequence is that if I leave Liferea running, it slowly spams me
with Authentication dialogs, sometimes stealing focus. My current
workaround is to not leave Liferea running, but to periodically launch
it, Update All, then close it when I'm done.

I'm willing to upgrade to 1.10 *if* the data format for Liferea (and
dependencies) is the same as for 1.8 (so that I can downgrade again if
need be.)

Thank you for your work on Liferea!

 - Tim McCormack

-- System Information:
Debian Release: 7.4
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.2.0-4-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages liferea depends on:
ii  gconf-service       3.2.5-1+build1
ii  gconf2              3.2.5-1+build1
ii  libatk1.0-0         2.4.0-2
ii  libc6               2.13-38+deb7u1
ii  libcairo2           1.12.2-3
ii  libgconf-2-4        3.2.5-1+build1
ii  libgdk-pixbuf2.0-0  2.26.1-1
ii  libglib2.0-0        2.33.12+really2.32.4-5
ii  libgtk2.0-0         2.24.10-2
ii  libice6             2:1.0.8-2
ii  libjson-glib-1.0-0  0.14.2-1
ii  libnotify4          0.7.5-1
ii  libpango1.0-0       1.30.0-1
ii  libsm6              2:1.2.1-2
ii  libsoup2.4-1        2.38.1-2
ii  libsqlite3-0        3.7.13-1+deb7u1
ii  libunique-1.0-0     1.1.6-4
ii  libwebkitgtk-1.0-0  1.8.1-3.4
ii  libxml2             2.8.0+dfsg1-7+nmu2
ii  libxslt1.1          1.1.26-14.1
ii  liferea-data        1.8.6-1.1

Versions of packages liferea recommends:
ii  curl      7.26.0-1+wheezy8
ii  dbus      1.6.8-1+deb7u1
ii  dbus-x11  1.6.8-1+deb7u1
ii  wget      1.13.4-3+deb7u1

Versions of packages liferea suggests:
ii  network-manager  0.9.4.0-10

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to