Skip to content

fix: prevent local loops when routing to the same address - #3625

Open
pplulee wants to merge 1 commit into
postalserver:mainfrom
pplulee:fix/prevent-local-route-loops
Open

pplulee wants to merge 1 commit into
postalserver:mainfrom
pplulee:fix/prevent-local-route-loops

Conversation

@pplulee

@pplulee pplulee commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

Summary

  • reject Address Endpoints that would deliver mail back to the route's own incoming address
  • apply the same check when adding extra endpoints or later changing an Address Endpoint address
  • compare addresses case-insensitively so User@Example.com cannot bypass user@example.com

This stops a misconfigured self-forward (route user@example.com pointing at Address Endpoint user@example.com) from generating unbounded mail.

Test plan

  • Create a route for user@example.com that forwards to Address Endpoint user@example.com and confirm save fails
  • Repeat with mixed-case addresses (User@Example.com) and confirm it is also rejected
  • Add the same address as an additional endpoint on an otherwise valid route and confirm save fails
  • Change an existing Address Endpoint to the route's own address and confirm save fails
  • Forward user@example.com to a different address and confirm save still succeeds

Made with Cursor

Reject address endpoints that deliver mail back to the route's own incoming address so a misconfigured self-forward cannot generate unbounded mail.

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants