Files
roundcube-ident_switch/SQL/mysql/2026021000.sql
Laurent Dinclaux fd9836c7ae Add custom auth, connection testing, preconfig_only, and security fixes
Major form improvements:
- Custom SMTP/Sieve credentials (separate username/password per protocol)
- Connection testing on save (IMAP, SMTP, Sieve) with localized errors
- preconfig_only mode to restrict domains to preconfigured entries
- Form POST value preservation on save errors (auth selects, passwords)
- Smart host placeholders (SMTP/Sieve default to IMAP host)

Security and bug:
- Fix password re-encryption bug (was comparing raw vs encrypted values)
- Fix XSS: escape label output in special folders form
- Fix parse_url() return value not checked for false
- Fix decrypt() failures not handled (fallback to empty string)
- Sanitize log output (remove raw POST data from log messages)
- Replace weak == comparisons with strict === (PHP and JS)

SQL changes:
- Consolidate 4 migrations (2026021000-03) into single 2026021000
- Remove now unused notify_sound_url column
- Add smtp_username, smtp_password, sieve_username, sieve_password columns
2026-02-10 20:50:05 +11:00

77 lines
1.4 KiB
SQL

-- Upgrade from v4.x to v5.x
-- Increase password column for encrypted values
ALTER TABLE `ident_switch`
MODIFY `password` varchar(255);
-- Add unique constraint on identity ID
ALTER TABLE `ident_switch`
ADD UNIQUE (`iid`);
-- Add Sieve support
ALTER TABLE `ident_switch`
ADD `sieve_host` varchar(64) AFTER `smtp_auth`;
ALTER TABLE `ident_switch`
ADD `sieve_port`
int
CHECK(`sieve_port` > 0 AND `sieve_port` <= 65535)
AFTER `sieve_host`;
ALTER TABLE `ident_switch`
ADD `sieve_auth`
smallint
NOT NULL
DEFAULT 1
AFTER `sieve_port`;
-- Add custom SMTP/Sieve credentials
ALTER TABLE `ident_switch`
ADD `smtp_username`
varchar(64)
DEFAULT NULL
AFTER `smtp_auth`;
ALTER TABLE `ident_switch`
ADD `smtp_password`
varchar(255)
DEFAULT NULL
AFTER `smtp_username`;
ALTER TABLE `ident_switch`
ADD `sieve_username`
varchar(64)
DEFAULT NULL
AFTER `sieve_auth`;
ALTER TABLE `ident_switch`
ADD `sieve_password`
varchar(255)
DEFAULT NULL
AFTER `sieve_username`;
-- Add notification settings
ALTER TABLE `ident_switch`
ADD `notify_check`
smallint
NOT NULL
DEFAULT 1
AFTER `sieve_password`;
ALTER TABLE `ident_switch`
ADD `notify_basic`
smallint
DEFAULT NULL
AFTER `notify_check`;
ALTER TABLE `ident_switch`
ADD `notify_sound`
smallint
DEFAULT NULL
AFTER `notify_basic`;
ALTER TABLE `ident_switch`
ADD `notify_desktop`
smallint
DEFAULT NULL
AFTER `notify_sound`;