Great Circle Associates Majordomo-Workers
(April 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: any reason restrict_post isn't checked *before* taboo?
From: pdc @ lunch . engr . sgi . com (Paul Close)
Date: Fri, 19 Apr 1996 10:45:52 -0700 (PDT)
To: Brent @ greatcircle . com (Brent Chapman)
Cc: cwilson @ splut . neu . sgi . com, majordomo-workers @ greatcircle . com
In-reply-to: <v0213050aad9ccdf04e89@[198.102.244.97]> from "Brent Chapman" at Apr 18, 1996 11:06:55 PM

>>> I have noticed that resend does admin and taboo checks before checking that
>>> the submitter is allowed to post.  Isn't this backwards?  I'm planning on
>>> switching the order in my resend, and wondered if there was some reason the
>>> checks were done in the current order?
>>
>> Yeah, because there could be an approved header or line hiding in
>> there someplace that would allow a "taboo" message to be sent...
> 
> But a valid "Approved:" _should_ allow a taboo message to be sent...
> "Approved: with a valid password should override almost any rejection,
> other than perhaps something fundamentally broken in the message
> (unbalanced "<" and ">" in an address, for example).
> 
> I don't think Paul is talking about the "Approved:" header checks; I think
> he's talking about the "is member of magic list of posters" checks, though
> I don't have the code available at the moment to check (I'm working offline
> from my Mac in a hotel room in Minneapolis).  For instance, the checks that
> allow you to create a list to which only subscribers can post by setting
> the approved-posters to be the list itself.

Yes, restrict_post.

> If that _is_ what Paul's talking about, then I think the code is already in
> the right order, and should not be changed.  Messages that trip the taboo
> and administrivia checks should require an explicit "Approved:" header and
> password, regardless of who they come from.

Yes, that's what I'm talking about.  But the order I'm talking about
is the order of the admin checks and the restrict-post checks.  I don't
understand what you thought I meant.

It makes sense to check if the poster has any rights to be there at all
before checking to see if they used any naughty words in their post, for
example.  This is NOT how majordomo does things today, and that's what I
think is broken.  Of course, if the message is approved, this is all moot.

Find out who we're talking to, then find out if there are problems with
the post.  The way resend is written today makes this very difficult and
awkward.
-- 
Paul Close <pdc@sgi.com>                          http://reality.sgi.com/pdc
			 No fate but what we make


References:
Indexed By Date Previous: Re: any reason restrict_post isn't checked *before* taboo?
From: Brent@GreatCircle.COM (Brent Chapman)
Next: Re: any reason restrict_post isn't checked *before* taboo?
From: Chan Wilson <cwilson@splut.neu.sgi.com>
Indexed By Thread Previous: Re: any reason restrict_post isn't checked *before* taboo?
From: Brent@GreatCircle.COM (Brent Chapman)
Next: Re: any reason restrict_post isn't checked *before* taboo?
From: Chan Wilson <cwilson@splut.neu.sgi.com>

Google
 
Search Internet Search www.greatcircle.com