From: Rick DeNatale Date: 2007-03-13T02:54:34+09:00 Subject: Re: Help with NET::SMTP On 3/12/07, Jenda Krynicky wrote: > Rick Denatale wrote: > > You should try either: > > > > smtp.open_message_stream('sender@mail.com', [email.untaint]) do > > > > or > > > > smtp.open_message_stream('sender@mail.com', email.untaint) do > > > > You might want to apply various tests to email to see if it is a valid > > email address, at least syntactically first, but this should get you > > around the current problem. > > Yeah, you may do this and create yet another web based mailer that will > allow everyone to send the email to anyone. The email variable contents > were tainted for a reason! "Solving" the issue by blind untaining is not > the brightest thing to do. You should validate the email first and (if > at all possible) make sure it's one of the allowed addresses or at least > that it's in the allowed domain(s). Which is what I suggested. We do try to be a little gentle in our suggestions in ruby-talk. Being able to send an e-mail is the first pre-requisite to building a verification system. In general you want to have a policy such as verifying e-mail addresses before, say subscribing someone, and only using that address again after it's been verified by a reply or a link back via http or the like, but in order to do that you need to be able to send that verification email, the rest moves from mechanism to policy, and as I understand the OPs problem he was having trouble figuring out the mechanism. -- Rick DeNatale My blog on Ruby http://talklikeaduck.denhaven2.com/