[ZendTo] No error when somebody tries to use ZendTo as an open relay

Jules Jules at Zend.To
Fri May 12 13:41:53 BST 2017


Well spotted!

It happened as a side-effect of the changes for the new upload progress bar.

The fix will be in the next beta release (hopefully due out by the end 
of the weekend), but if you want a fix now, just replace your existing 
/opt/zendto/templates/show_dropoff.tpl with the one attached (once 
you've gunzip-ed it!). No need to restart httpd/apache2 or anything, it 
will just start using it.

Thanks for reporting it!
Jules.

On 12/05/2017 12:26, Santiago Garcia Mantinan wrote:
> Hi!
>                                                                                                                                                                                                 
> I'm updating our ZendTo setup and while testing the new setup I have found
> that when somebody from outside (gmail account) tries to send a file to
> somebody who is also an outsider (another gmail account), he is not able to
> send it (great) but he doesn't get the error he should:
> ErrorWillNotSend = "You must be logged in as a Southampton user in order to drop-off a file for a non-Southampton user.<br />&nbsp;<br />Return to the ZendTo main menu to log in and then try again."
>                                                                                                                                                                                                 
> Instead he just gets the normal page without the error, and the page says
> "No files in the dropoff... something is amiss!"
>                                                                                                                                                                                                 
> The page is the right one but misses the "You must be logged" message on
> top, this is with 4.27-1, the old 4.12 version was working ok.
>                                                                                                                                                                                                 
> Is anybody else seeing this problem?
>                                                                                                                                                                                                 
> Regards.

Jules

-- 
Julian Field MEng CEng CITP MBCS MIEEE MACM

'All the art of living lies in a fine mingling of letting go,
  and holding on.' - Henry Ellis

www.Zend.To
Twitter: @JulesFM
PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654

-------------- next part --------------
A non-text attachment was scrubbed...
Name: show_dropoff.tpl.gz
Type: application/x-gzip
Size: 1985 bytes
Desc: not available
Url : http://mailman.ecs.soton.ac.uk/pipermail/zendto/attachments/20170512/be41d67c/attachment.gz 


More information about the ZendTo mailing list