Modify

Opened 21 months ago

Last modified 4 days ago

#13312 accepted defect

Password reset and e-mail verification mails are sent out to smtp_public_cc addresses on Trac 1.2

Reported by: Frau Boonekamp Owned by: Ryan J Ollos
Priority: highest Component: AccountManagerPlugin
Severity: blocker Keywords:
Cc: Thomas Moschny Trac Release:

Description (last modified by Frau Boonekamp)

We have found that AccountManager emails have been sent to our public mailing list, once we upgraded to Trac 1.2.2.

See this password email and this user verification mail.

The issue seems to be that the new notification system no longer uses the get_smtp_address method, so the override will no longer work.

For now we have disabled sending emails to the public cc mailing list.

Attachments (0)

Change History (9)

comment:1 Changed 21 months ago by Frau Boonekamp

Description: modified (diff)

comment:2 Changed 21 months ago by Ryan J Ollos

See also #13074. Please share your [notification] and [account-manager] sections, with sensitive information obfuscated.

comment:3 Changed 21 months ago by Ryan J Ollos

Status: newaccepted

comment:4 Changed 21 months ago by anonymous

[account-manager]
account_changes_notify_addresses = 
authentication_url = 
db_htdigest_realm = temp
force_passwd_change = disabled
hash_method = HtDigestHashMethod
htdigest_file = /srv/trac/XXX/auth/trac.htdig
htdigest_realm = haiku
notify_actions = 
password_store = HtDigestStore
persistent_sessions = enabled
refresh_passwd = disabled
register_check = BasicCheck,EmailCheck,RegExpCheck,UsernamePermCheck,RegistrationFilterAdapter
user_lock_max_time = 86400
verify_email = enabled

[notification]
smtp_public_cc = XXX@freelists.org
maxheaderlen = 78
mime_encoding = qp
smtp_enabled = enabled
smtp_from = trac@XXX.org
smtp_from_author = enabled
smtp_replyto = noreply@XXX.org
smtp_server = localhost
use_public_cc = disabled
Last edited 21 months ago by Ryan J Ollos (previous) (diff)

comment:5 in reply to:  4 Changed 21 months ago by Frau Boonekamp

Would it be an option to rewrite the configuration temporarily while sending, like is done with the use_public_cc configuration setting?

comment:6 Changed 21 months ago by Ryan J Ollos

We need to add support for the new notification system in Trac: #13124. I hope to address that in the coming weeks.

comment:7 Changed 18 months ago by David Bonnin

any news? i just made mistake at job with that today, lol.

comment:8 Changed 15 months ago by Thomas Moschny

Cc: Thomas Moschny added

Also seeing this with 1.2.2 and notification.smtp_always_cc set.

comment:9 Changed 9 months ago by Amar Takhar

This was fixed in ticket #8796.

Modify Ticket

Change Properties
Set your email in Preferences
Action
as accepted The owner will remain Ryan J Ollos.

Add Comment


E-mail address and name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.