Hello,
I am creating this bug report for one of our users. I don't know which version he uses and if it's still unfixed.
See also in crudeoauth https://github.com/univention/crudeoauth/issues/1 and some user of XOAUTH2 had the same issue (https://github.com/moriyoshi/cyrus-sasl-xoauth2/issues/9#issuecomment-1223583671 ):
The origin of the warning message "mbsync: "Warning: SASL wants more steps despite successful IMAP authentication. Ignoring..." is:
static int
process_sasl_step( imap_store_t *ctx, int rc, const char *in, uint in_len,
sasl_interact_t *interact, const char **out, uint *out_len )
{
imap_server_conf_t *srvc = ctx->conf->server;
while (rc == SASL_INTERACT) {
if (process_sasl_interact( interact, srvc ) < 0)
return -1;
rc = sasl_client_step( ctx->sasl, in, in_len, &interact, out, out_len );
}
if (rc == SASL_CONTINUE) {
ctx->sasl_cont = 1;
} else if (rc == SASL_OK) {
ctx->sasl_cont = 0;
} else {
error( "Error performing SASL authentication step: %s\n", sasl_errdetail( ctx->sasl ) );
return -1;
}
return 0;
}
static void
done_sasl_auth( imap_store_t *ctx, imap_cmd_t *cmd ATTR_UNUSED, int response )
{
if (response == RESP_OK && ctx->sasl_cont) {
sasl_interact_t *interact = NULL;
const char *out;
uint out_len;
int rc = sasl_client_step( ctx->sasl, NULL, 0, &interact, &out, &out_len );
if (process_sasl_step( ctx, rc, NULL, 0, interact, &out, &out_len ) < 0)
warn( "Warning: SASL reported failure despite successful IMAP authentication. Ignoring...\n" );
else if (out_len > 0)
warn( "Warning: SASL wants more steps despite successful IMAP authentication. Ignoring...\n" );
}
imap_open_store_authenticate2_p2( ctx, NULL, response );
}
So this looks like that mbsync doesn't do all required steps. It would, if the SASL module would return SASL_INTERACT but the OAUTHBEARER specs doesn't mention to use this in the authentication flow.