From: Minero Aoki Date: 2005-04-08T08:48:46+09:00 Subject: Re: Net::SMTP/mod_ruby SecurityError Hi, In mail "Re: Net::SMTP/mod_ruby SecurityError" Richard Turner wrote: > > I have an application that uses mod_ruby and I need to be able to have > > it email a message to an address specified by a user using a web form. I > > seem to have everything set-up fine, I run the entered email address > > through a validation process before continuing so I'm confident it's > > safe to untaint it, but sendmessage() still raises a SecurityError. > Unless I'm very much mistaken I've tracked the problem to the > send_message() method in smtp.rb. This method calls Array#flatten on its > to_addrs parameter which, it seems, causes any elements in that array > that had been explicitly untainted to become tainted again. Later, in > send0(), a SecurityError is then thrown (if $SAFE > 0) regardless of any > programmer's steps to untaint email addresses. > > So, my question becomes, is there a way for me to untaint a validated > email address and ensure that it stays untainted even when the array > it's in is flattened by Net::SMTP.send_message? Untaint all addresses explicitly: smtp.send_messages from.untaint, to.map {|a| a.untaint }, str Best Regards, Minero Aoki