Re: Re: Improving mail() 5th parameter handling
| From: | Christoph M. Becker | Date: | Mon, 09 Jan 2017 16:56:49 +0000 |
| Subject: | Re: Re: Improving mail() 5th parameter handling | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-97634@lists.php.net to get a copy of this message | ||
On 09.01.2017 at 17:23, Nikita Popov wrote:
> On Sun, Jan 8, 2017 at 11:56 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
>
>> Hi Nikita and all,
>>
>> On Mon, Jan 9, 2017 at 7:31 AM, Nikita Popov <nikita.ppv@gmail.com> wrote:
>>
>>> Without this option, how do you specify the envelope sender? That seems
>>> to be the primary use-case.
>>
>>
>> Indeed, it seems it is.
>> It could be set by mail.force_extra_parameters. I agree this isn't a great
>> way to do, but the obstacle may help users to notice risks.
>>
>> Parameters must be validated still, but it will help in most cases and I
>> don't mind writing patch for arrayed 'addtional_parameter'. In this case,
>> I'll just fix this as normal bug fix and post proposed patch before commit.
>> Any comments on this?
>
> Allowing an array for additional_parameter sounds reasonable. Before
> committing a patch, please lets make sure that people from phpmailer and
> other people familiar with the recent exploits verify it.
See bug #73842.
--
Christoph M. Becker