Files
lasuite-messages/docs
Sylvain Zimmerandjbpenrath bf6a6160b0 🔒️(global) harden access scoping and outbound requests
Several endpoints acted on ids, hosts or ports without checking the
caller was entitled to them:
- deny API actions with no object to check unless the view declares
  it does its own access check (checks_access_in_view)
- require mailbox access for mailbox_id on message list, and match the
  requested mailbox in thread search results
- image proxy: only ports 80/443 (every redirect hop included), per-user
  rate limit (API_IMAGE_PROXY_THROTTLE_RATE), private cache, no second
  URL decoding
- SSRF-check per-domain SMTP relays and connect to the checked IP
  (IPv4 first); internal relays need SSRF_ALLOWED_HOSTS
- validate MailDomain.custom_settings against a schema
- restrict IMAP import ports (MESSAGES_IMPORT_IMAP_ALLOWED_PORTS,
  143/993 by default)
- refuse MTA requests with a 401 instead of a 500 when MDA_API_SECRET
  is unset
- only use the Referer hostname in widget message subjects
- scope the DNS check endpoint through the admin queryset
2026-09-29 12:10:41 +02:00
..