mirror of
https://github.com/suitenumerique/messages.git
synced 2026-09-30 21:55:00 +02:00
Several endpoints acted on ids, hosts or ports without checking the caller was entitled to them: - deny API actions with no object to check unless the view declares it does its own access check (checks_access_in_view) - require mailbox access for mailbox_id on message list, and match the requested mailbox in thread search results - image proxy: only ports 80/443 (every redirect hop included), per-user rate limit (API_IMAGE_PROXY_THROTTLE_RATE), private cache, no second URL decoding - SSRF-check per-domain SMTP relays and connect to the checked IP (IPv4 first); internal relays need SSRF_ALLOWED_HOSTS - validate MailDomain.custom_settings against a schema - restrict IMAP import ports (MESSAGES_IMPORT_IMAP_ALLOWED_PORTS, 143/993 by default) - refuse MTA requests with a 401 instead of a 500 when MDA_API_SECRET is unset - only use the Referer hostname in widget message subjects - scope the DNS check endpoint through the admin queryset