Files
roundcube-ident_switch/SQL/postgres/2026021000.sql
Laurent Dinclaux fd9836c7ae Add custom auth, connection testing, preconfig_only, and security fixes
Major form improvements:
- Custom SMTP/Sieve credentials (separate username/password per protocol)
- Connection testing on save (IMAP, SMTP, Sieve) with localized errors
- preconfig_only mode to restrict domains to preconfigured entries
- Form POST value preservation on save errors (auth selects, passwords)
- Smart host placeholders (SMTP/Sieve default to IMAP host)

Security and bug:
- Fix password re-encryption bug (was comparing raw vs encrypted values)
- Fix XSS: escape label output in special folders form
- Fix parse_url() return value not checked for false
- Fix decrypt() failures not handled (fallback to empty string)
- Sanitize log output (remove raw POST data from log messages)
- Replace weak == comparisons with strict === (PHP and JS)

SQL changes:
- Consolidate 4 migrations (2026021000-03) into single 2026021000
- Remove now unused notify_sound_url column
- Add smtp_username, smtp_password, sieve_username, sieve_password columns
2026-02-10 20:50:05 +11:00

54 lines
1.2 KiB
SQL

-- Upgrade from v4.x to v5.x
-- Increase password column for encrypted values
ALTER TABLE ident_switch
ALTER COLUMN password TYPE varchar(255);
-- Add unique constraint on identity ID
ALTER TABLE ident_switch
ADD CONSTRAINT ident_switch_iid_unique UNIQUE (iid);
CREATE INDEX IF NOT EXISTS IX_ident_switch_iid ON ident_switch(iid);
-- Add Sieve support
ALTER TABLE ident_switch
ADD sieve_host varchar(64);
ALTER TABLE ident_switch
ADD sieve_port
integer
CHECK(sieve_port > 0 AND sieve_port <= 65535);
ALTER TABLE ident_switch
ADD sieve_auth
smallint
NOT NULL
DEFAULT(1);
-- Add custom SMTP/Sieve credentials
ALTER TABLE ident_switch ADD COLUMN smtp_username varchar(64) DEFAULT NULL;
ALTER TABLE ident_switch ADD COLUMN smtp_password varchar(255) DEFAULT NULL;
ALTER TABLE ident_switch ADD COLUMN sieve_username varchar(64) DEFAULT NULL;
ALTER TABLE ident_switch ADD COLUMN sieve_password varchar(255) DEFAULT NULL;
-- Add notification settings
ALTER TABLE ident_switch
ADD notify_check
smallint
NOT NULL
DEFAULT 1;
ALTER TABLE ident_switch
ADD notify_basic
smallint
DEFAULT NULL;
ALTER TABLE ident_switch
ADD notify_sound
smallint
DEFAULT NULL;
ALTER TABLE ident_switch
ADD notify_desktop
smallint
DEFAULT NULL;