mirror of
https://github.com/inverse-inc/sogo.git
synced 2026-10-08 13:27:15 +00:00
generateMessageID: appended the substring following the last '@' without sanitizing it, so a sender value such as 'Doe, John <a@b>' produced 'Message-Id: <uuid@b>>' with a duplicated closing bracket on calendar invitations. A nil domain also left the message-id unterminated. The domain part is now cut at the first address delimiter or whitespace - a domain is a single token, and anything else would allow header injection through generated message-ids. Fixes #6201
46 lines
1.3 KiB
Objective-C
46 lines
1.3 KiB
Objective-C
#import "SOGoTest.h"
|
|
|
|
#import "Mailer/NSString+Mail.h"
|
|
|
|
static NSString *
|
|
MessageIDShape(NSString *mailOrDomain)
|
|
{
|
|
NSString *messageID = [NSString generateMessageID: mailOrDomain];
|
|
|
|
return [@"<UUID" stringByAppendingString: [messageID substringFromIndex: 37]];
|
|
}
|
|
|
|
@interface TestNSString_plus_Mail : SOGoTest
|
|
@end
|
|
|
|
@implementation TestNSString_plus_Mail
|
|
|
|
- (void) test_generateMessageID_fromAddressOrDomain
|
|
{
|
|
testEquals(MessageIDShape(@"user@example.org"), @"<UUID@example.org>");
|
|
testEquals(MessageIDShape(@"Example.ORG"), @"<UUID@example.org>");
|
|
}
|
|
|
|
- (void) test_generateMessageID_fromSenderWithDisplayName
|
|
{
|
|
testEquals(MessageIDShape(@"Doe, John <user@example.org>"), @"<UUID@example.org>");
|
|
testEquals(MessageIDShape(@"Doe, John <user@example.org> (work)"), @"<UUID@example.org>");
|
|
testEquals(MessageIDShape(@"user@example.org>"), @"<UUID@example.org>");
|
|
}
|
|
|
|
- (void) test_generateMessageID_rejectsInjectedDomains
|
|
{
|
|
testEquals(MessageIDShape(@"user@example.org\r\nBcc: victim"),
|
|
@"<UUID@example.org>");
|
|
testEquals(MessageIDShape(@"user@example.org Bcc: victim"),
|
|
@"<UUID@example.org>");
|
|
}
|
|
|
|
- (void) test_generateMessageID_withoutDomain
|
|
{
|
|
testEquals(MessageIDShape(@""), @"<UUID>");
|
|
testEquals(MessageIDShape(nil), @"<UUID>");
|
|
}
|
|
|
|
@end
|