Subject: The mailing list for listmasters using Sympa
List archive
Re: [sympa-users] mail confirmation is NOT equivalent to password authentication
- From: Olivier Salaün - CRU <address@concealed>
- To: Peter Farmer <address@concealed>
- Cc: address@concealed
- Subject: Re: [sympa-users] mail confirmation is NOT equivalent to password authentication
- Date: Tue, 22 Aug 2006 17:54:41 +0200
That's a known problem we have for the sending process. Things are complicated because the mail distribution process is delegated by wwsympa to the sympa.pl process ; therefore wwsympa leaves the message as a file in the msg/ spool. What we need is assert sympa.pl that the author of the message has been properly authenticated.
I realize that we don't have an entry for this bug in our tracking system, please add one :
http://sourcesup.cru.fr/tracker/?group_id=23
Peter Farmer wrote:
There appears to be a discrepancy in the documented and actual functionality
of the authorization rules for send scenarii :
[...]
This seems like 'what you would expect' , but in fact you cannot actually post via the web if you only allow md5 authorisation (i.e. 'mail confirmation') in the scenarii. I tried (many different ways) and failed. I then checked the code in sympa.pl v5.2 [...]
hence for sending messages, mail confirmation (on the mail interface) is NOT equivalent to password authentication (on the web interface). [...]
My issue is why should they have to go through the multi step mail confirmation process when they have already authenticated themselves to the appropriate level ? At the moment they do .
-
[sympa-users] mail confirmation is NOT equivalent to password authentication,
Peter Farmer, 08/22/2006
-
Re: [sympa-users] mail confirmation is NOT equivalent to password authentication,
Olivier Salaün - CRU, 08/22/2006
- Re: [sympa-users] mail confirmation is NOT equivalent to password authentication, Peter Farmer, 08/22/2006
-
Re: [sympa-users] mail confirmation is NOT equivalent to password authentication,
Olivier Salaün - CRU, 08/22/2006
Archive powered by MHonArc 2.6.19+.