Forums / General / prevent "spoofing" sender's email address in tip a friend

prevent "spoofing" sender's email address in tip a friend

Author Message

Herman Hardenbol

Thursday 09 February 2006 3:09:26 am

I have the standard "Tip a friend" option turned on. In my intranet installation everybody needs to logon. How could I force users to use there own user name en user email as a sender and not changed the prefilled name and email? (in ezpublish 3.6.2)

I am looking for a more secure solution than just making the HTML fields read only.

Any small hint is more than welcome. Thanks a lot.

Martin Lekvall

Friday 10 February 2006 2:39:58 am

Hi

This is an idea, not tested.
You might want to override the tipafriend-template and make the email and name-formfields hidden. The value of these fields are prefilled with address automagicaly if user is logged in, right?

For usabillity i guess printing out that "tip will sent from John Doe (john@foo.bar)" or similar is a good idea.

/martin

EzP 3.5.0, OE 2.0
RH-EL3 2.4, mySql 4.1.7, php 4.3.9, apache 1.3.33

Herman Hardenbol

Sunday 12 February 2006 1:54:46 pm

Thanks Martin. I was just about to hack the kernel, when I found that the kernel supplies the username and useremail for the logged in user account when name and email are not sent from the HTML form.

In /templates/content/tipafriend.tpl I have removed the input fields for sender's name and sender's email and that's all!! I am happy. :-)

Nice solution for my intranet environment where everybody needs to login and everybody has an email address.

eZ debug

Timing: Jan 18 2025 19:11:07
Script start
Timing: Jan 18 2025 19:11:07
Module start 'content'
Timing: Jan 18 2025 19:11:07
Module end 'content'
Timing: Jan 18 2025 19:11:08
Script end

Main resources:

Total runtime0.3234 sec
Peak memory usage2,048.0000 KB
Database Queries141

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0118 587.8516180.8203
Module start 'content' 0.01180.0131 768.671993.8203
Module end 'content' 0.02490.2984 862.4922522.2031
Script end 0.3234  1,384.6953 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00411.2543200.0002
Check MTime0.00150.4674200.0001
Mysql Total
Database connection0.00090.286610.0009
Mysqli_queries0.255278.91481410.0018
Looping result0.00170.52791390.0000
Template Total0.297892.110.2978
Template load0.00090.290010.0009
Template processing0.296891.765610.2968
Override
Cache load0.00060.187110.0006
Sytem overhead
Fetch class attribute can translate value0.00090.272410.0009
XML
Image XML parsing0.00030.096110.0003
General
dbfile0.00742.2984200.0004
String conversion0.00000.002130.0000
Note: percentages do not add up to 100% because some accumulators overlap

CSS/JS files loaded with "ezjscPacker" during request:

CacheTypePacklevelSourceFiles
CSS0extension/community/design/community/stylesheets/ext/jquery.autocomplete.css
extension/community_design/design/suncana/stylesheets/scrollbars.css
extension/community_design/design/suncana/stylesheets/tabs.css
extension/community_design/design/suncana/stylesheets/roadmap.css
extension/community_design/design/suncana/stylesheets/content.css
extension/community_design/design/suncana/stylesheets/star-rating.css
extension/community_design/design/suncana/stylesheets/syntax_and_custom_tags.css
extension/community_design/design/suncana/stylesheets/buttons.css
extension/community_design/design/suncana/stylesheets/tweetbox.css
extension/community_design/design/suncana/stylesheets/jquery.fancybox-1.3.4.css
extension/bcsmoothgallery/design/standard/stylesheets/magnific-popup.css
extension/sevenx/design/simple/stylesheets/star_rating.css
extension/sevenx/design/simple/stylesheets/libs/fontawesome/css/all.min.css
extension/sevenx/design/simple/stylesheets/main.v02.css
extension/sevenx/design/simple/stylesheets/main.v02.res.css
JS0extension/ezjscore/design/standard/lib/yui/3.17.2/build/yui/yui-min.js
extension/ezjscore/design/standard/javascript/jquery-3.7.0.min.js
extension/community_design/design/suncana/javascript/jquery.ui.core.min.js
extension/community_design/design/suncana/javascript/jquery.ui.widget.min.js
extension/community_design/design/suncana/javascript/jquery.easing.1.3.js
extension/community_design/design/suncana/javascript/jquery.ui.tabs.js
extension/community_design/design/suncana/javascript/jquery.hoverIntent.min.js
extension/community_design/design/suncana/javascript/jquery.popmenu.js
extension/community_design/design/suncana/javascript/jScrollPane.js
extension/community_design/design/suncana/javascript/jquery.mousewheel.js
extension/community_design/design/suncana/javascript/jquery.cycle.all.js
extension/sevenx/design/simple/javascript/jquery.scrollTo.js
extension/community_design/design/suncana/javascript/jquery.cookie.js
extension/community_design/design/suncana/javascript/ezstarrating_jquery.js
extension/community_design/design/suncana/javascript/jquery.initboxes.js
extension/community_design/design/suncana/javascript/app.js
extension/community_design/design/suncana/javascript/twitterwidget.js
extension/community_design/design/suncana/javascript/community.js
extension/community_design/design/suncana/javascript/roadmap.js
extension/community_design/design/suncana/javascript/ez.js
extension/community_design/design/suncana/javascript/ezshareevents.js
extension/sevenx/design/simple/javascript/main.js

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1pagelayout.tpl<No override>extension/sevenx/design/simple/templates/pagelayout.tplEdit templateOverride template
 Number of times templates used: 1
 Number of unique templates used: 1

Time used to render debug report: 0.0001 secs