Edgewall Software
Modify

Opened 14 years ago

Last modified 4 days ago

#10579 new enhancement

Do not use "anonymous" updater's email in ticket notification From

Reported by: Mark Potter <mpotter@…> Owned by:
Priority: normal Milestone: next-major-releases
Component: notification Version:
Severity: normal Keywords: updater notification from
Cc: Branch:
Release Notes:
API Changes:
Internal Changes:

Description

Originally an additional suggestion to #8360 in comment:11:

With the "improvement" mentioned in comment:9, it would be possible for a malefactor to use a Trac system to send emails (new tickets or comments) that would appear to come from someone else.

Suggestion: The new smtp_from_author feature should only use email addresses from authenticated users.

Attachments (0)

Change History (3)

comment:1 by Remy Blank, 14 years ago

Milestone: next-major-0.1X

comment:2 by Philippe Cloutier <chealer@…>, 4 days ago

Thank you for reporting

Is this specific to tickets?

Such a feature should only be offered with trusted addresses. And as tracked in ticket #4286, even addresses of registered users cannot be trusted.

This comment is from Philippe "Chealer" Cloutier. All of my comments and contributions in this ticket are offered under the terms of CC0 1.0 (unless otherwise noted).

comment:3 by Jun Omae, 4 days ago

Even if the email address is trusted, it is difficult to enable the smtp_from_author feature on the Internet with SPF, DKIM, and DMARC. This feature will only be useful if all users belong to a single domain.

Modify Ticket

Change Properties
Set your email in Preferences
Action
as new The ticket will remain with no owner.
The ticket will be disowned.
as The resolution will be set. Next status will be 'closed'.
The owner will be changed from (none) to anonymous. Next status will be 'assigned'.

Add Comment


E-mail address and name can be saved in the Preferences .
 
Note: See TracTickets for help on using tickets.