Merge pull request #14187 from atm-john/10.0_fix_email_spoofing
Fix email spoofing - with hidden conf
This commit is contained in:
commit
eb7f3b81d3
@ -420,7 +420,20 @@ class CMailFile
|
|||||||
//$this->message->setFrom(array('john@doe.com' => 'John Doe'));
|
//$this->message->setFrom(array('john@doe.com' => 'John Doe'));
|
||||||
if (!empty($from)) {
|
if (!empty($from)) {
|
||||||
try {
|
try {
|
||||||
|
if (! empty($conf->global->MAIN_FORCE_DISABLE_MAIL_SPOOFING)) {
|
||||||
|
// Prevent email spoofing for smtp server with a strict configuration
|
||||||
|
$regexp = '/([a-z0-9_\.\-\+])+\@(([a-z0-9\-])+\.)+([a-z0-9]{2,4})+/i'; // This regular expression extracts all emails from a string
|
||||||
|
$emailMatchs = preg_match_all($regexp, $from, $adressEmailFrom);
|
||||||
|
$adressEmailFrom = reset($adressEmailFrom);
|
||||||
|
if ($emailMatchs !== false && filter_var($conf->global->MAIN_MAIL_SMTPS_ID, FILTER_VALIDATE_EMAIL) && $conf->global->MAIN_MAIL_SMTPS_ID !== $adressEmailFrom)
|
||||||
|
{
|
||||||
|
$result = $this->message->setFrom($conf->global->MAIN_MAIL_SMTPS_ID);
|
||||||
|
} else {
|
||||||
$result = $this->message->setFrom($this->getArrayAddress($from));
|
$result = $this->message->setFrom($this->getArrayAddress($from));
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
$result = $this->message->setFrom($this->getArrayAddress($from));
|
||||||
|
}
|
||||||
} catch (Exception $e) {
|
} catch (Exception $e) {
|
||||||
$this->errors[] = $e->getMessage();
|
$this->errors[] = $e->getMessage();
|
||||||
}
|
}
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user