SASL (Secure Authentication and Security Layer) support.
Sasl is an abstract base class for pluggable authentication mechanisms used by connection-based mail services. It implements the Secure Authentication part of SASL, providing a challenge-response interface that can be invoked multiple times until authentication completes.
Non-SASL authentication mechanisms that fit the same challenge-response design (such as LOGIN and NTLM) are also wrapped in Sasl subclasses to simplify their use.
Instances are created via the for_service factory function, which looks up the named mechanism. The main API is challenge, which takes a server challenge token and returns the client's response token. A base64 convenience wrapper, challenge_base64, is provided for protocols that exchange base64-encoded tokens.
Available built-in mechanisms include: ANONYMOUS, CRAM-MD5, DIGEST-MD5, GSSAPI (Kerberos), LOGIN, NTLM, PLAIN, POPB4SMTP, and XOAUTH2 variants.