プロジェクト

全般

プロフィール

Vote #72555

未完了

Mailhandler reply security hole

Admin Redmine さんがほぼ4年前に追加. ほぼ4年前に更新.

ステータス:
New
優先度:
通常
担当者:
-
カテゴリ:
Email receiving_29
対象バージョン:
-
開始日:
2022/05/09
期日:
進捗率:

0%

予定工数:
category_id:
29
version_id:
0
issue_org_id:
11946
author_id:
63837
assigned_to_id:
0
comments:
4
status_id:
1
tracker_id:
1
plus1:
0
affected_version:
closed_on:
affected_version_id:
47
ステータス-->[New]

説明

I don't know if this is the expected behavior but I recognized that it's possible to reply to an issue of another project than the one specified in the /etc/aliases file.
Assume I have an /etc/aliases file with a line like this one:
foo: "| /opt/redmine/extra/mail_handler/rdm-mailhandler.rb --url=http://localhost:8080 --key=XXXX --project=foo --unknown-user=ignore"

Now I send an email to foo@someurl.net with subject "Re:[#123]" and 123 is the id of an issue that is not part of project foo, anyway the email is not refused.

I would expect that this should not be possible because I limited that emailadress to project foo.


journals

This would need to be a flag in the command line I would think: there are many of us that have project set as a _default_ box, but are still listening to system-wide replies on this e-mail address.
--------------------------------------------------------------------------------
Indeed. The @--project@ option is for setting the default project for new issues, not to restrict the replies to a given project.
--------------------------------------------------------------------------------
As far as I know there is no option _--issue_ yet, even in the new redmine 2.1.0.
Is there any need so I could make a request for a future release?
--------------------------------------------------------------------------------

--------------------------------------------------------------------------------

Admin Redmine さんがほぼ4年前に更新

  • カテゴリEmail receiving_29 にセット

他の形式にエクスポート: Atom PDF

いいね!0
いいね!0