Skip to content

Developer manual: validate and rate-limit outgoing mail in email.rst #15683

Description

@miaulalala

developer_manual/digging_deeper/email.rst shows how to send mail, but nothing about abuse: an app can easily turn an instance into a spam relay.

  • Validate recipients with IMailer::validateMailAddress().
  • Rate-limit endpoints that send mail (#[UserRateLimit], #[AnonRateLimit], or ILimiter, see digging_deeper/security.rst).
  • Add a note: anonymous / public users must not be able to make the instance send mail to an address they typed in, or only with a strict rate limit.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions