Skip to content

fix(email): reinforcement of the validator and skip invalid address when sending alerts#78

Open
kevin-blackbird wants to merge 1 commit intowebgriffe:masterfrom
kevin-blackbird:feature/email-format-verification
Open

fix(email): reinforcement of the validator and skip invalid address when sending alerts#78
kevin-blackbird wants to merge 1 commit intowebgriffe:masterfrom
kevin-blackbird:feature/email-format-verification

Conversation

@kevin-blackbird
Copy link

Hi,

On the last version for Sylius 1.X, version 4.1.0, we had a bug blocking the sending of alerts.

Indeed, if the email format was incorrect, we had an RfcComplianceException.
A person try an injection with this kind of email : mauralien21@gmail.com'&&sleep(27*1000)*ckfqsx&&' just by changing the input type from email to text, the backend Email validator accept this email.
To prevent that I add it the redtriction mode : Email::VALIDATION_MODE_STRICT

On alert sending, I had a try catch to no stop alert sending on email error.

If you accept this PR, can we have an 4.1.1 or 4.2.0 tags for Sylius 1 pls ?

Have a nice day !

Kind regards,
Kévin

@kevin-blackbird
Copy link
Author

Hi,

Is there an update with this fix planned for soon ?

Kind regards,
Kévin

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think you can just try/catch the line that throw the exception and do a continue with a log before it. Please remove also the comment, if you want you can add the line Invalid email address, continue to the next one to the log with the exception message

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants