[Bug] SMTP BCC recipients exposed in message headers

#9 · closed · 2 comments

View on GitHub ↗

ZheniaTrochun

## Problem BCC recipients are incorrectly included in the email message headers sent to the server. This exposes the full list of private recipients to everyone who receives the email. This behaviour violates SMTP protocol (RFC 5321/5322). ## Code to reproduce ```lua local mail = require "resty.mail" local mailer_opts = { host = <host>, port = <port> } local mailer = mail.new(mailer_opts) local request = { from = "[email protected]", to = { "[email protected]" }, subject = "test mail", bcc = { "[email protected]" }, html = "<h1>hello there</h1>" } mailer:send(request) ``` ## Expected behaviour Receiver don't see that mail was "BCCd" to `[email protected]`. ## Actual behaviour Receiver sees full list of BCC receivers. ## Most probable root cause List of BCC receivers included into SMPT message headers.

Comments

GUI

@ZheniaTrochun: Doh! Thanks for catching this! It's possible senders weren't leaked if certain SMTP servers were being used (like if Postfix's [cleanup](https://www.postfix.org/cleanup.8.html) was in the mix), but yeah, this definitely shouldn't have been happening. This should be fixed by https://github.com/GUI/lua-resty-mail/pull/10 and is released in v1.2.0 now.

ZheniaTrochun

Thank you a lot for a such quick fix!