prosgarz35 opened a new pull request, #3217:
URL: https://github.com/apache/james-project/pull/3217

   ### Why this is needed
   
   RFC 3461 §4.1 requires servers to **reject** malformed DSN parameters 
(`NOTIFY`, `ORCPT`, `ENVID`) with a syntax error — not to drop the connection. 
Right now, `DSNMailParameterHook` and `DSNRcptParameterHook` don't catch the 
`IllegalArgumentException` thrown by `DsnParameters` on invalid input, so it 
propagates all the way to Netty, which treats it as fatal and **disconnects the 
TCP session**.
   
   In practice: any client that sends a slightly malformed DSN parameter — e.g. 
`RCPT TO:<a@x> NOTIFY=BOGUS`, or `ORCPT` without the `rfc822;` prefix, or a 
non-xtext `ENVID` — gets its entire SMTP session killed instead of a `501` it 
could recover from. This is a spec-compliance bug and a minor DoS vector (one 
bad parameter costs the client its whole connection, not just the command).
   
   ### What changed
   
   Both hooks now catch `IllegalArgumentException` around the existing 
`DsnParameters` parsing calls and return a `501 5.5.4` response, reusing the 
same `HookResult` pattern already used elsewhere in this module 
(`MailSizeEsmtpExtension.SYNTAX_ERROR`). No new abstractions, no changes to 
`DsnParameters` itself — its "throw on invalid input" contract is correct and 
tested at that layer; it just needs to be caught at the SMTP-protocol boundary.
   
   `RET` (already `Optional`-based, silently ignoring invalid values) is left 
untouched — out of scope for this fix.
   
   ### Testing
   
   - 9 new unit tests (`DSNMailParameterHookTest`, `DSNRcptParameterHookTest`) 
covering both the accept and reject paths.
   - Full module build: `BUILD SUCCESS`, 16/16 tests pass, including the 
existing `DSNTest` integration suite (7 tests, real SMTP client) — **no 
regressions**.
   
   ### Files changed
   ```
   
server/protocols/protocols-smtp/src/main/java/org/apache/james/smtpserver/dsn/DSNMailParameterHook.java
   
server/protocols/protocols-smtp/src/main/java/org/apache/james/smtpserver/dsn/DSNRcptParameterHook.java
   
server/protocols/protocols-smtp/src/test/java/org/apache/james/smtpserver/dsn/DSNMailParameterHookTest.java
  (new)
   
server/protocols/protocols-smtp/src/test/java/org/apache/james/smtpserver/dsn/DSNRcptParameterHookTest.java
  (new)
   ```


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to