Quote:
Originally Posted by merk
Fair enough, though the system is open to abuse if you think about it. I wonder if there is another solution to either make it harder or impossible to abuse.
|
I think the abuse would require
all the following conditions:
1. Enabling auto processing option
2.
And enabling usergroupid change option
3.
And allowing members to see other members email addressess (or them finding out the email addresses from the members themselves)
4.
And being able to forge emails with correct bounce syntax.
But an alternative would be to ignore forged email headers. I may write some pre-checks, and/or allow the option to call user-defined scripts, like SpamAssasin and the like, to allow returning a true or false answer, and ignore emails based on that answer.