fix(mail): keep master SMTP credentials for CLI without session password - #219
Open
TDannhauer wants to merge 1 commit into
Open
fix(mail): keep master SMTP credentials for CLI without session password#219TDannhauer wants to merge 1 commit into
TDannhauer wants to merge 1 commit into
Conversation
horde-alarms runs with user_admin authentication (name only, no password). With username_auth/password_auth enabled, getConfig() previously overwrote the configured master SMTP credentials with the admin username and an empty password, causing intermittent Server denied authentication errors until a web session successfully sent the alarm mail. Only apply session credentials when a non-empty session password is present; otherwise retain the configured master username/password.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
user_adminhas an auth name but no session passwordhorde-alarmsfrom authenticating to SMTP with an empty password underusername_auth/password_authMotivation
horde-alarmsinitializes Horde withuser_admin, which sets an admin identity without credentials. With mailerusername_auth/password_authenabled,Horde_Core_Factory_Mail::getConfig()overwrote the configured master SMTP credentials with that admin username andgetAuthCredential('password')(empty/false). SMTP then returnedServer denied authentication. Because failed alarm mails never setinternal['mail']['sent'], the same alarm was retried on every cron run until a web session with real credentials sent it successfully — producing intermittent multi-hour error bursts.Changes
password_authis enabled but no session password exists, retain master username and passwordsmtp_credentialshook results only overlay the omitted keysMailFactoryTestcovering CLI fallback, session overlay, and empty-password handlingTest plan
vendor/bin/phpunit -c vendor/horde/core/phpunit.xml.dist --bootstrap vendor/autoload.php vendor/horde/core/test/Unit/Factory/MailFactoryTest.phphorde-alarmswhile a mail alarm is pending; confirm SMTP auth succeeds with master credentials*_authis enabled