Repository navigation
fix(mail): validate connector SMTP recipient mailbox - #1769
Draft
seonghobae wants to merge 3 commits into
Draft
seonghobae wants to merge 3 commits into
seonghobae wants to merge 3 commits into
Conversation
Contributor
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This was referenced Sep 24, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current authority — 2026-09-24 KST
develop@042b0c70531b229af3acbd0421a2f23098d848b3/ tree8fde14381aaa430eeaaf61151dab6f6800127cd3f84c4fefa7586274c86a5032373d851a8c7f84d2822543bb37070a63437d60c190b01161503003cee07ff4df5f5daa107daec4d331c70e7192163770Verified product gap
The authenticated API send path models
toas PydanticEmailStr, but protectedbackend/runner/local_mail_adapters.pyaccepted any non-emptytostring and handed it toEmailMessageParams. PythonEmailMessageparsing can reinterpret malformed address text rather than preserve caller intent. A standalone current-runtime reproduction turnsuser@example.com> AUTH=<attacker@example.cominto parseduser@example.cominstead of rejecting it.That is an external-input ACL mismatch: the local connector can execute a recipient different from the literal request while returning no invalid-payload error. This PR owns only that connector payload → SMTP mailbox boundary.
RED → minimal causal fix
822543bb...adds focused tests requiring:user@example.com> AUTH=<attacker@example.comrecipient to returninvalid_payloadbeforesend_emailis called;recipient@EXAMPLE.COMto be normalized torecipient@example.combefore provider use.The protected parent only checks non-empty text, so both expectations are RED there.
e07ff4df...adds_required_smtp_mailboxto the local adapter, uses the already-pinnedemail-validator==2.3.0withcheck_deliverability=False, translatesEmailNotValidErrorinto the existing fixed invalid-payload contract, and passes only the normalized mailbox downstream. The new helper is documented and both accepted/rejected paths are covered.f84c4fef...adds the doctoring/traceability record with the rejected alternatives, reproduction boundary, commands, and primary/standards references.Dependency-security boundary
Protected source still pins
aiosmtplib==5.1.2. Upstream 5.1.3 addresses CVE-2026-90467, an ESMTP parameter-injection flaw in directmail/rcpt/vrfy/expn/sendmailaddress handling. Naruon's current_send_pinned_smtp_messageusesSMTP.send_message(message), so this PR does not claim CVE-2026-90467 is currently exploitable through the Naruon send path.Dependency adoption remains separate owner work. Dependabot #1749 mixes aiosmtplib 5.1.3 with 75 other backend updates; #1752 already defines aiosmtplib as an independent update. Do not copy that dependency delta into this product-boundary PR.
Evidence boundary
Exact
f84c4fef...generated fresh Application CI35989827882, Security35989827763, CodeQL35989827794, Bandit35989827796, Semgrep35989827833, and Docker35989828169; all are queued/pending at this observation. No predecessor receipt transfers. No qualifying post-last-push independent approval exists yet.Focused repository target after the fix:
cd backend python -m pytest -q -W error \ tests/test_runner_mail_recipient_validation.py \ tests/test_runner_mail_adapters.py python -m ruff check \ runner/local_mail_adapters.py \ tests/test_runner_mail_recipient_validation.pyKeep Draft until the unchanged final head has terminal required checks, zero valid actionable review findings, and qualifying independent review. No dependency source-copy, workflow mutation, gate weakening, self-approval, force push/destructive rebase, source-neutral wake commit, or predecessor receipt transfer.