Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

Always remember that you are unique. Just like everyone else.


dovenet / Synchronet Programming / DDMsgReader: When replying to a message, @-codes are now expanded in t

SubjectAuthor
* DDMsgReader: When replying to a message, @-codes are now expanded in tRob Swindell
`* DDMsgReader: When replying to a message, @-codes are nowexpanded in tNelgin
 `- DDMsgReader: When replying to a message, @-codes are nowexpandedDigital Man

1
DDMsgReader: When replying to a message, @-codes are now expanded in t

<638A4815.46144.syncprog@vert.synchro.net>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=152&group=DOVE-Net.Synchronet_Programming#152

  copy link   Newsgroups: DOVE-Net.Synchronet_Programming
From: rob.swindell@VERT (Rob Swindell)
To: GitLab note in main/sbbs
Subject: DDMsgReader: When replying to a message, @-codes are now expanded in t
Message-ID: <638A4815.46144.syncprog@vert.synchro.net>
Date: Fri, 2 Dec 2022 03:46:45 -0800
X-Comment-To: GitLab note in main/sbbs
Path: rocksolidbbs.com!not-for-mail
Organization: Vertrauen
Newsgroups: DOVE-Net.Synchronet_Programming
X-FTN-PID: Synchronet 3.20a-Linux v320a_dev/5b30c2d10 Nov 11 2022 GCC 12.2.0
X-FTN-MSGID: 46144.syncprog@1:103/705 27f03255
X-FTN-CHRS: CP437 2
WhenImported: 20221202104645-0800 41e0
WhenExported: 20221202161819-0800 41e0
ExportedFrom: VERT syncprog 46144
Content-Type: text/plain; charset=IBM437
Content-Transfer-Encoding: 8bit
 by: Rob Swindell - Fri, 2 Dec 2022 11:46 UTC

https://gitlab.synchro.net/main/sbbs/-/merge_requests/226#note_2916

@-codes in messages posted by non-Sysops are normally *never* expanded on Synchronet due to security issues (e.g. a non-sysop posts @HANGUP@, or @DELAY:99999@ for example). Similarly, any message received over a message network should never have any @-codes expanded.

This commit seems to introduce a security concern and raises general concerns about how SlyEdit handles @-codes currently.

---
■ Synchronet ■ Vertrauen ■ Home of Synchronet ■ [vert/cvs/bbs].synchro.net

Re: DDMsgReader: When replying to a message, @-codes are nowexpanded in t

<20221209002956.73761087@wibble.sysadmininc.com>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=171&group=DOVE-Net.Synchronet_Programming#171

  copy link   Newsgroups: DOVE-Net.Synchronet_Programming
From: nelgin@VERT/EOTLBBS (Nelgin)
To: Rob Swindell
Subject: Re: DDMsgReader: When replying to a message, @-codes are nowexpanded in t
Message-ID: <20221209002956.73761087@wibble.sysadmininc.com>
Date: Thu, 8 Dec 2022 17:29:56 -0600
X-Comment-To: Rob Swindell
Path: rocksolidbbs.com!not-for-mail
Organization: End Of The Line BBS
Newsgroups: DOVE-Net.Synchronet_Programming
In-Reply-To: <638A4815.46144.syncprog@vert.synchro.net>
References: <638A4815.46144.syncprog@vert.synchro.net>
X-FTN-PID: Synchronet 3.20a-Linux v320a_dev/7e48fc77d Dec 3 2022 GCC 9.4.0
X-FTN-MSGID: 46163.syncprog@1:103/705 27f8c0af
X-FTN-REPLY: 46144.syncprog@1:103/705 27f03255
X-FTN-CHRS: CP437 2
WhenImported: 20221208223156-0800 41e0
WhenExported: 20221209041835-0800 41e0
ExportedFrom: VERT syncprog 46163
WhenImported: 20221209002956-0600 4168
WhenExported: 20221209003154-0600 4168
ExportedFrom: EOTLBBS dove-syncprog 18078
X-Newsreader: Claws Mail 4.1.1git14 (GTK 3.24.20; x86_64-pc-linux-gnu)
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
 by: Nelgin - Thu, 8 Dec 2022 23:29 UTC

On Fri, 2 Dec 2022 10:46:45 -0800
"Rob Swindell" <rob.swindell@VERT> wrote:

> https://gitlab.synchro.net/main/sbbs/-/merge_requests/226#note_2916
>
> @-codes in messages posted by non-Sysops are normally *never*
> expanded on Synchronet due to security issues (e.g. a non-sysop posts
> @HANGUP@, or @DELAY:99999@ for example). Similarly, any message
> received over a message network should never have any @-codes
> expanded.
>
> This commit seems to introduce a security concern and raises general
> concerns about how SlyEdit handles @-codes currently.

The reason I requested this is because when I responded to an email on
a BBS that was an autogenerated welcome mesasge, the @BBS@ and @ALIAS@
codes were expanded but when I replied, the quoted message had @BBS@
and @ALIAS@.

I think the intent should be that the @codes are converted into the
actual text at the time the message is sent. If the sysop wants to
change their BBS name or the user changes their alias post-sending of
the original, then tough.

I agree that @-codes shouldn't be expanded when sent from a user but if
coming from the system or sysop, then expand them and put the text in.
Problem solved.
--
End Of The Line BBS - Plano, TX
telnet endofthelinebbs.com 23
---
� Synchronet � End Of The Line BBS - endofthelinebbs.com

Re: DDMsgReader: When replying to a message, @-codes are nowexpanded

<63937179.46164.syncprog@vert.synchro.net>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=172&group=DOVE-Net.Synchronet_Programming#172

  copy link   Newsgroups: DOVE-Net.Synchronet_Programming
From: digital.man@VERT (Digital Man)
To: Nelgin
Subject: Re: DDMsgReader: When replying to a message, @-codes are nowexpanded
Message-ID: <63937179.46164.syncprog@vert.synchro.net>
Date: Fri, 9 Dec 2022 02:33:45 -0800
X-Comment-To: Nelgin
Path: rocksolidbbs.com!not-for-mail
Organization: Vertrauen
Newsgroups: DOVE-Net.Synchronet_Programming
In-Reply-To: <20221209002956.73761087@wibble.sysadmininc.com>
References: <20221209002956.73761087@wibble.sysadmininc.com>
X-FTN-PID: Synchronet 3.20a-Linux v320a_dev/a791c24b4 Dec 4 2022 GCC 12.2.0
X-FTN-MSGID: 46164.syncprog@1:103/705 27f95bcd
X-FTN-REPLY: 46163.syncprog@1:103/705 27f8c0af
X-FTN-CHRS: CP437 2
WhenImported: 20221209093345-0800 41e0
WhenExported: 20221209101831-0800 41e0
ExportedFrom: VERT syncprog 46164
Content-Type: text/plain; charset=IBM437
Content-Transfer-Encoding: 8bit
 by: Digital Man - Fri, 9 Dec 2022 10:33 UTC

Re: Re: DDMsgReader: When replying to a message, @-codes are nowexpanded i
By: Nelgin to Rob Swindell on Fri Dec 09 2022 12:29 am

> On Fri, 2 Dec 2022 10:46:45 -0800
> "Rob Swindell" <rob.swindell@VERT> wrote:
>
> > https://gitlab.synchro.net/main/sbbs/-/merge_requests/226#note_2916
>
> > @-codes in messages posted by non-Sysops are normally *never*
> > expanded on Synchronet due to security issues (e.g. a non-sysop posts
> > @HANGUP@, or @DELAY:99999@ for example). Similarly, any message
> > received over a message network should never have any @-codes
> > expanded.
>
> > This commit seems to introduce a security concern and raises general
> > concerns about how SlyEdit handles @-codes currently.
>
> The reason I requested this is because when I responded to an email on
> a BBS that was an autogenerated welcome mesasge, the @BBS@ and @ALIAS@
> codes were expanded but when I replied, the quoted message had @BBS@
> and @ALIAS@.
>
> I think the intent should be that the @codes are converted into the
> actual text at the time the message is sent. If the sysop wants to
> change their BBS name or the user changes their alias post-sending of
> the original, then tough.
>
> I agree that @-codes shouldn't be expanded when sent from a user but if
> coming from the system or sysop, then expand them and put the text in.
> Problem solved.

Yeah, that sounds preferably and a pretty easy change (at elast for those 2 specific @-codes) in exec/newuser.js. Create a new gitlab issue/request for this?
--
digital man (rob)

This Is Spinal Tap quote #36:
Bobbi Flekman: Money talks, and bullshit walks.
Norco, CA WX: 48.5°F, 75.0% humidity, 0 mph E wind, 0.00 inches rain/24hrs
---
■ Synchronet ■ Vertrauen ■ Home of Synchronet ■ [vert/cvs/bbs].synchro.net


dovenet / Synchronet Programming / DDMsgReader: When replying to a message, @-codes are now expanded in t

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor