Mailer Plus Log
The module does not hide sensitive information in the emails it records. An administrator could see one time login links for any account and use them to log in as that person. They could read hidden data and change data.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youAny site using this module where an attacker has the access right to view the mail log.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Mailer Plus Log to 1.2.7.
For developers: what the fix changed
The fix introduces an email redactor service in `src/EmailRedactor.php` to remove sensitive login links from email bodies. This redaction is applied before saving the log entry in the `preSave` method of `src/Entity/SymfonyMailerLog.php`.
Also in this release Added tests, updated documentation, and added CSpell dictionary words.
.gitlab-ci.yml+2 −0README.md+31 −0src/EmailRedactor.php+138 −0 fixsrc/EmailRedactorInterface.php+36 −0 fixsrc/Entity/SymfonyMailerLog.php+59 −0 fixsrc/Entity/SymfonyMailerLogInterface.php+10 −0 fixsrc/Plugin/Field/FieldFormatter/SymfonyMailerLogHtmlBody.php+13 −0 fixsrc/RedactionMode.php+21 −0 fixsymfony_mailer_log.api.php+67 −0 fixsymfony_mailer_log.install+16 −0 fixsymfony_mailer_log.permissions.yml+3 −0 fixsymfony_mailer_log.post_update.php+77 −0 fix