Skip to content

Replica: Add blank option to server IP-pool select; prompt for rule form#73

Open
lucaforni wants to merge 9 commits into
main-modalsourcefrom
vaibhavheda-postal-main
Open

Replica: Add blank option to server IP-pool select; prompt for rule form#73
lucaforni wants to merge 9 commits into
main-modalsourcefrom
vaibhavheda-postal-main

Conversation

@lucaforni
Copy link
Copy Markdown

Questa PR replica la PR originale: postalserver#3561

Autore originale: @vaibhavheda
Branch originale: main
Repository originale: vaibhavheda/postal


Summary

The IP-pool collection_select on the server form (and rule form) had no blank option, so once a pool was assigned, there was no UI path to clear it. The model already accepts a nil ip_pool_id — only the view
stood in the way.

  • Server form: adds include_blank: "No specific pool (use rules / default)" (server pool is optional).
  • Rule form: adds prompt: "Select an IP pool" (rule pool is required, so prompt is more appropriate than blank).

Test plan

  • Picking the blank option in the server form persists servers.ip_pool_id = NULL.
  • After unset, new QueuedMessage rows have ip_address_id = NULL.
  • Toggle works in both directions.
  • Rule form shows the prompt for new rules; existing rules render unchanged.

adamcooke and others added 9 commits February 1, 2026 14:48
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
The app-wide CSP already blocks inline script execution, but the HTML
preview iframe for a stored email was same-origin and un-sandboxed, and
the html_raw response had no per-action hardening. Add a sandbox on the
iframe and tighten the CSP on html_raw to script-src 'none' with
nosniff and no-referrer so the preview has defence in depth against a
future CSP bypass or regression.

Relates to GHSA-f6g9-8555-cw28.
The /img/<server>/<message> endpoint accepted a src=<url> query
parameter and proxied the body of that URL back to the caller. Nothing
in the codebase ever produces a src= parameter — the parser only
inserts a plain tracking pixel and rewrites href links — so this branch
is dead code inherited from the original AppMail import.

Drop the src branch: requests with src now return 400. The no-src path
that serves the tracking pixel and records loads is unchanged, and a
spec covers both the pixel-serving path and the removed branch.
The endpoint and domain option helpers interpolated model attributes
straight into an HTML string before marking the whole buffer html_safe.
Wrap the interpolations in h() so untrusted attributes can't break out
of the surrounding tag.

Also stop the helpers glob in rails_helper from eagerly requiring
_spec.rb files so helper specs can live under spec/helpers/, and add a
small application helper spec covering the escape behaviour.
url_with_return_to only checked that return_to started with a forward
slash, which also allowed protocol-relative values like //host and
/\host. Rails 7.1 already refuses to follow those via redirect_to, so
the user just saw a 500. Reject the same shapes in the helper instead
so we fall back to the default URL cleanly.

Adds a sessions request spec covering the rejected shapes plus the
happy-path relative redirect.
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants