Add custom auth, connection testing, preconfig_only, and security fixes
Major form improvements: - Custom SMTP/Sieve credentials (separate username/password per protocol) - Connection testing on save (IMAP, SMTP, Sieve) with localized errors - preconfig_only mode to restrict domains to preconfigured entries - Form POST value preservation on save errors (auth selects, passwords) - Smart host placeholders (SMTP/Sieve default to IMAP host) Security and bug: - Fix password re-encryption bug (was comparing raw vs encrypted values) - Fix XSS: escape label output in special folders form - Fix parse_url() return value not checked for false - Fix decrypt() failures not handled (fallback to empty string) - Sanitize log output (remove raw POST data from log messages) - Replace weak == comparisons with strict === (PHP and JS) SQL changes: - Consolidate 4 migrations (2026021000-03) into single 2026021000 - Remove now unused notify_sound_url column - Add smtp_username, smtp_password, sieve_username, sieve_password columns
This commit is contained in:
@@ -82,3 +82,13 @@ $config['ident_switch.round_robin'] = false;
|
||||
* Default: false (warning is displayed).
|
||||
*/
|
||||
$config['ident_switch.hide_notifier_warning'] = false;
|
||||
|
||||
/*
|
||||
* Restrict account switching to preconfigured domains only.
|
||||
* When enabled, the ident_switch form is hidden for identities whose email
|
||||
* domain does not match any entry in 'ident_switch.preconfig'.
|
||||
* Users can still create Roundcube identities (name, signature, etc.) but
|
||||
* cannot configure server connections for non-preconfigured domains.
|
||||
* Default: false (all domains allowed).
|
||||
*/
|
||||
$config['ident_switch.preconfig_only'] = false;
|
||||
|
||||
Reference in New Issue
Block a user