Download the PHP package horde/sasl without Composer
On this page you can find all versions of the php package horde/sasl. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Package sasl
Short Description SASL authentication library
License LGPL-2.1-only
Homepage https://www.horde.org
Informations about the package sasl
horde/Sasl
A role-generic, protocol-agnostic SASL (RFC 4422) library for PHP 8.1+ It implements both the client and server side of each mechanism.
What it is
horde/Sasl provides the authentication exchange mechanism.
State machines that consume and produce raw octets. It intentionally does not
handle IMAP/SMTP/POP3/ManageSieve wire framing (base64, tagging, line
continuation). That is a protocol adapter's job, built on top of this
library in the consuming package.
Supported mechanisms, client and server unless noted:
ANONYMOUS(RFC 4505)PLAIN,LOGINCRAM-MD5,DIGEST-MD5SCRAM-SHA-1,SCRAM-SHA-256,SCRAM-SHA-512(+ their-PLUSchannel-binding variants)OAUTHBEARER,XOAUTH2(client only)EXTERNAL
Notable design points:
- Mechanisms are pure octet-in/octet-out state machines. No base64 or line framing inside the library.
- Real SCRAM channel binding (GS2 header +
ChannelBindingProvider), not a hardcodedn,,. - SASLprep username normalization via
horde/stringprep. ClientMechanismFactory/ServerMechanismFactoryplus aNegotiatorandSaslPolicyfor mechanism selection and minimum-strength TLS gating.
See doc/CAPABILITIES.md for a detailed capability
comparison against pear/Auth_SASL2, the closest prior PHP SASL library.
History
horde/sasl was developed to replace the aging pear/Auth_SASL2 as well as inline implementations in horde/imap_client, horde/smtp and horde/managesieve libraries. It implements the server side according to RFC as far as it makes sense.
Installation
Testing
All versions of sasl with dependencies
horde/exception Version ^3 || dev-FRAMEWORK_6_0
horde/stringprep Version ^2 || dev-FRAMEWORK_6_0
ext-hash Version *
ext-json Version *