Changed ACL semantics: The ACL is processed only if the posting didn't

have a valid password. If it did, the mail is going through in any
case and the ACL is not tested.
This commit is contained in:
Peter Simons 2001-01-19 16:46:25 +00:00
parent 73ed1ee547
commit ac901a4e1c

View File

@ -92,6 +92,16 @@ hermes_main(char * incoming_mail, const char * listname)
if (FindBodyPassword(MailStruct) != 0)
exit(1);
if (isValidPostingPassword(MailStruct->Approve, listname) == FALSE)
{
/* If no valid posting password has been provided, the mail is
subject to the ACL mechanism. Please note that the ACL may
actually set a correct posting password via the 'approve'
command. So just because there wasn't a valid posting
password here, it doesn't mean there might not be after ACL
processing is over. That's why we check the posting
password again below. */
if (checkACL(MailStruct, listname, &operation, &parameter) != 0)
{
syslog(LOG_ERR, "checkACL() failed with an error.");
@ -108,11 +118,11 @@ hermes_main(char * incoming_mail, const char * listname)
case 1:
return 0;
}
}
if (isValidPostingPassword(MailStruct->Approve, listname) == FALSE)
{
/* No valid password found. Reject the article, if the list is
of type 'moderated'. */
/* Reject the article, if the list is of type 'moderated'. */
if (ListConfig->listtype == LIST_MODERATED)
{