Compare commits

...
Author SHA1 Message Date
FreddleSpl0it 91d3b7246a [Web] Minor hardening across web UI and nginx 2026-08-18 09:08:17 +02:00
FreddleSpl0itandGitHub b362c7105d Merge pull request #7425 from mailcow/feat/redis-7.4.10
[Redis] Update to 7.4.10
2026-08-18 08:14:21 +02:00
FreddleSpl0it 555e7ed706 [Redis] Update to 7.4.10 2026-08-18 08:12:32 +02:00
FreddleSpl0itandGitHub 59e2a9ac77 Merge pull request #7423 from mailcow/fix/7418
[Dovecot] Remove legacy DeltaChat auto-filing sieve rule
2026-08-17 08:41:18 +02:00
6 changed files with 17 additions and 8 deletions
@@ -116,6 +116,7 @@ location ~ \.php$ {
include /etc/nginx/fastcgi_params; include /etc/nginx/fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_param PATH_INFO $fastcgi_path_info;
fastcgi_param HTTP_X_REAL_IP $remote_addr;
# trusted internal-auth marker; empty for external clients (see nginx.conf map) # trusted internal-auth marker; empty for external clients (see nginx.conf map)
fastcgi_param SOGO_AUTH_INTERNAL $sogo_auth_internal; fastcgi_param SOGO_AUTH_INTERNAL $sogo_auth_internal;
fastcgi_read_timeout 3600; fastcgi_read_timeout 3600;
+6 -6
View File
@@ -380,13 +380,13 @@ if (isset($_SESSION['mailcow_cc_role']) && ($_SESSION['mailcow_cc_role'] == "adm
else { else {
$state = state_nomatch; $state = state_nomatch;
} }
$state .= '<br />' . $current[$data_field[$current['type']]]; $state .= '<br />' . htmlspecialchars($current[$data_field[$current['type']]]);
} }
if ($current['type'] == 'TXT' && if ($current['type'] == 'TXT' &&
stripos($current['txt'], 'v=dmarc') === 0 && stripos($current['txt'], 'v=dmarc') === 0 &&
$record[2] == $dmarc_link) { $record[2] == $dmarc_link) {
$current['txt'] = str_replace(' ', '', $current['txt']); $current['txt'] = str_replace(' ', '', $current['txt']);
$state = $current[$data_field[$current['type']]] . state_optional; $state = htmlspecialchars($current[$data_field[$current['type']]]) . state_optional;
} }
elseif ($current['type'] == 'TXT' && elseif ($current['type'] == 'TXT' &&
stripos($current['txt'], 'v=spf') === 0 && stripos($current['txt'], 'v=spf') === 0 &&
@@ -396,7 +396,7 @@ if (isset($_SESSION['mailcow_cc_role']) && ($_SESSION['mailcow_cc_role'] == "adm
if (in_array($ip, $rslt) && in_array(expand_ipv6($ip6), $rslt)) { if (in_array($ip, $rslt) && in_array(expand_ipv6($ip6), $rslt)) {
$state = state_good; $state = state_good;
} }
$state .= '<br />' . $current[$data_field[$current['type']]] . state_optional; $state .= '<br />' . htmlspecialchars($current[$data_field[$current['type']]]) . state_optional;
} }
elseif ($current['type'] == 'TXT' && elseif ($current['type'] == 'TXT' &&
stripos($current['txt'], 'v=dkim') === 0 && stripos($current['txt'], 'v=dkim') === 0 &&
@@ -426,7 +426,7 @@ if (isset($_SESSION['mailcow_cc_role']) && ($_SESSION['mailcow_cc_role'] == "adm
if ($state == state_nomatch) { if ($state == state_nomatch) {
$state = array(); $state = array();
foreach ($currents as $current) { foreach ($currents as $current) {
$state[] = $current[$data_field[$current['type']]]; $state[] = htmlspecialchars($current[$data_field[$current['type']]]);
} }
$state = implode('<br />', $state); $state = implode('<br />', $state);
} }
@@ -436,7 +436,7 @@ if (isset($_SESSION['mailcow_cc_role']) && ($_SESSION['mailcow_cc_role'] == "adm
<td>%s</td> <td>%s</td>
<td class="dns-found">%s</td> <td class="dns-found">%s</td>
<td class="dns-recommended">%s</td> <td class="dns-recommended">%s</td>
</tr>', $record[0], $record[1], $record[2], $state); </tr>', htmlspecialchars($record[0]), htmlspecialchars($record[1]), $record[2], $state);
$record[3] = explode('<br />', $state); $record[3] = explode('<br />', $state);
} }
@@ -477,7 +477,7 @@ if (isset($_SESSION['mailcow_cc_role']) && ($_SESSION['mailcow_cc_role'] == "adm
} }
?> ?>
</table> </table>
<a id='download-zonefile' class="btn btn-sm btn-secondary visible-xs-block visible-sm-inline visible-md-inline visible-lg-inline mb-4" style="margin-top:10px" data-zonefile="<?=base64_encode($dns_data);?>" download='<?=$_GET['domain'];?>.txt' type='text/csv'>Download</a> <a id='download-zonefile' class="btn btn-sm btn-secondary visible-xs-block visible-sm-inline visible-md-inline visible-lg-inline mb-4" style="margin-top:10px" data-zonefile="<?=base64_encode($dns_data);?>" download='<?=htmlspecialchars($_GET['domain']);?>.txt' type='text/csv'>Download</a>
<script> <script>
var zonefile_dl_link = document.getElementById('download-zonefile'); var zonefile_dl_link = document.getElementById('download-zonefile');
var zonefile = atob(zonefile_dl_link.getAttribute('data-zonefile')); var zonefile = atob(zonefile_dl_link.getAttribute('data-zonefile'));
+1 -1
View File
@@ -591,7 +591,7 @@ function logger($_data = false) {
$type = $return['type']; $type = $return['type'];
$msg = null; $msg = null;
if (isset($return['msg'])) { if (isset($return['msg'])) {
$msg = json_encode($return['msg'], JSON_UNESCAPED_UNICODE); $msg = json_encode($return['msg'], JSON_UNESCAPED_UNICODE | JSON_HEX_TAG | JSON_HEX_AMP | JSON_HEX_APOS | JSON_HEX_QUOT);
} }
$call = null; $call = null;
if (isset($return['log'])) { if (isset($return['log'])) {
+2
View File
@@ -1169,6 +1169,7 @@ jQuery(function($){
if (item === null) { return true; } if (item === null) { return true; }
item.user = escapeHtml(item.user); item.user = escapeHtml(item.user);
item.call = escapeHtml(item.call); item.call = escapeHtml(item.call);
if (item.msg) item.msg = escapeHtml(item.msg);
item.task = '<code>' + item.task + '</code>'; item.task = '<code>' + item.task + '</code>';
item.type = '<span class="badge fs-6 bg-' + item.type + '">' + item.type + '</span>'; item.type = '<span class="badge fs-6 bg-' + item.type + '">' + item.type + '</span>';
}); });
@@ -1176,6 +1177,7 @@ jQuery(function($){
$.each(data, function (i, item) { $.each(data, function (i, item) {
if (item === null) { return true; } if (item === null) { return true; }
item.username = escapeHtml(item.username); item.username = escapeHtml(item.username);
item.real_rip = escapeHtml(item.real_rip);
item.service = '<div class="badge fs-6 bg-secondary">' + item.service.toUpperCase() + '</div>'; item.service = '<div class="badge fs-6 bg-secondary">' + item.service.toUpperCase() + '</div>';
}); });
} else if (table == 'general_syslog') { } else if (table == 'general_syslog') {
+6
View File
@@ -4,6 +4,7 @@ require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/prerequisites.inc.php';
if (!isset($_SESSION['mailcow_cc_role'])) { if (!isset($_SESSION['mailcow_cc_role'])) {
$_SESSION['oauth2_request'] = $_SERVER['REQUEST_URI']; $_SESSION['oauth2_request'] = $_SERVER['REQUEST_URI'];
header('Location: /?oauth'); header('Location: /?oauth');
exit;
} }
$request = OAuth2\Request::createFromGlobals(); $request = OAuth2\Request::createFromGlobals();
@@ -24,6 +25,11 @@ if (!isset($_POST['authorized'])) {
exit; exit;
} }
if (empty($_SESSION['mailcow_cc_username'])) {
header('Location: /?oauth');
exit;
}
// print the authorization code if the user has authorized your client // print the authorization code if the user has authorized your client
$is_authorized = ($_POST['authorized'] == '1'); $is_authorized = ($_POST['authorized'] == '1');
$oauth2_server->handleAuthorizeRequest($request, $response, $is_authorized, $_SESSION['mailcow_cc_username']); $oauth2_server->handleAuthorizeRequest($request, $response, $is_authorized, $_SESSION['mailcow_cc_username']);
+1 -1
View File
@@ -42,7 +42,7 @@ services:
- mysql - mysql
redis-mailcow: redis-mailcow:
image: redis:7.4.6-alpine image: redis:7.4.10-alpine
entrypoint: ["/bin/sh","/redis-conf.sh"] entrypoint: ["/bin/sh","/redis-conf.sh"]
volumes: volumes:
- redis-vol-1:/data/ - redis-vol-1:/data/