Skip to content

Fix: mailto notifier rejects valid email addresses containing dots - #1745

Closed
prarit wants to merge 1 commit into
OpenPrinting:masterfrom
prarit:fix_dot
Closed

prarit wants to merge 1 commit into
OpenPrinting:masterfrom
prarit:fix_dot

Conversation

@prarit

@prarit prarit commented Oct 6, 2026

Copy link
Copy Markdown

A regression was found in the mailto notifier in which valid email addresses containing dots/periods would be rejected. For example, "mailto:user@example.com" would now be rejected.

Add a dot to the allowed characters.

Fixes #1744
Reference: 611d1bd ("Validate notification email addresses and fix sendmail usage (GHSA-r4wf-366f-f6g3)")

Signed-off-by: Prarit Bhargava prarit@redhat.com

…riods

A regression was found in the mailto notifier in which valid email
addresses containing dots/periods would be rejected.  For example,
"mailto:user@example.com" would now be rejected.

Add a dot to the allowed characters.

Fixes OpenPrinting#1744
Reference: 611d1bd ("Validate notification email addresses and fix sendmail usage (GHSA-r4wf-366f-f6g3)")
Signed-off-by: Prarit Bhargava <prarit@redhat.com>

@zdohnal zdohnal left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds reasonable, @michaelrsweet wdyt?

@michaelrsweet michaelrsweet self-assigned this Oct 6, 2026
@michaelrsweet

Copy link
Copy Markdown
Member

Actually I think we want the following change to make it clearer with the validation:

diff --git a/notifier/mailto.c b/notifier/mailto.c
index 2f118a674..fe0aa58f9 100644
--- a/notifier/mailto.c
+++ b/notifier/mailto.c
@@ -262,13 +262,14 @@ copy_validate_address(
 
       saw_at = 1;
     }
-    else if (*bufptr == '.' && (bufptr == buffer || bufptr[-1] == '.' || bufptr[-1] == '@'))
+    else if (*bufptr == '.')
     {
      /*
       * dot-atom-text doesn't allow consecutive periods...
       */
 
-      goto bad_address;
+      if (bufptr == buffer || bufptr[-1] == '.' || bufptr[-1] == '@')
+       goto bad_address;
     }
     else if (!strchr("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz"
                      "0123456789!#$%&\'*+-/=?^_`{|}~", *bufptr))

@michaelrsweet
michaelrsweet self-requested a review October 6, 2026 13:01

@michaelrsweet michaelrsweet left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See comment.

@michaelrsweet

Copy link
Copy Markdown
Member

[master 4487b5a] Fix mailto validation (Issue #1744)

[2.4.x 14c424937] Fix mailto validation (Issue #1744)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Regression: mailto notifier rejects valid email addresses containing dots/periods

3 participants