Re: Untaint $local_part, $domain and other variables

Slavko via Exim-users <[email protected]>
Newsgroups gmane.mail.exim.user
Message-ID <[email protected]>
Dňa 16. 9. o 5:25 Ian Z via Exim-users napísal(a):
> On Sun, Sep 14, 2025 at 01:09:08PM -0400, Emilio Augusto Lazo Zaia via Exim-users wrote:

> As for the others: you can use the envelope_to_add and return_path_add
> options on the transport. Then the information you are trying to
> obtain from the variables will be available in the email header. Your
> script can parse the header.

IMO, the question is why one have to parse the message again, when all 
these are already available, but (ehm) unusable...

Anyway, the tainting idea is/was to make exim more secure, but 
processing whole message again (especially by home made script) can open 
more new/unknown problems.

regards

-- 
Slavko
https://www.slavino.sk/


-- 
## subscription configuration (requires account):
##   https://lists.exim.org/mailman3/postorius/lists/exim-users.lists.exim.org/
## unsubscribe (doesn't require an account):
##   [email protected]
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.