Re: Register user - problem with header in email validation.

posts: 1817 Catalan Countries

Dear Michal.Kress:

From tiki-devel email list, a developer fixed it for you, it seems.

Can you confirm that this change fixes your issue in your server?



On 06/08/12 15:23, Jean-Marc Libs wrote:
Hi Xavi,

My opinion is, any supplementary newline in a mail subject will be interpreted as a security issue by the mail server because that makes it possible to inject any SMTP header extra line. So it's not surprising some modern mail servers detect and reject that.

It's probably a bug in a Tiki tpl file (usually a subject file starting with a a comment all alone before the subject line which smarty then changes into a blank line.

Found it, I guess:
$ more templates/mail/confirm_user_email_subject.tpl
{* $Id: confirm_user_email_subject.tpl 33949 2011-04-14 05:13:23Z chealer $ *}
{tr}Confirm your email at %s{/tr}

You can tell him to remove the top line and just leave a one-line {tr}Confirm your email at %s{/tr} in file templates/mail/confirm_user_email_subject.tpl

I did it in revision 42533.

I hope that's it, as opposed to some faulty subject line being hand-crafted in some php file.


Upcoming Events

No records to display