You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Unsafe to merge: the inbound-mail authentication change permits unauthorized public report updates.
What we checked:
Reproduced the authentication-related proof for P1, producing authentication-results reproduction, baseline output, forged message effects, and focused inbound test outputs.
Validated the P2 migration proof by running the migration script, capturing seed and result outputs, and reviewing the focused PostgreSQL test outcomes.
Validated the API runtime contract and CI-harness-like reproduction by building the image and running the smoke test inside, yielding image-smoke success and a runtime-layout-ok with pnpm/corepack absent.
Demonstrated a header provenance test using a spoofed inbound message; the focused unit run reported authVerdict 'pass' and 109 passing tests, noting that header provenance is not covered by focused tests.
Completed the PostgreSQL integration run, showing inbound/outbound deliveries for two test cases and 18 tests passing.
An attacker can put Authentication-Results: mx.cloudflare.net; dmarc=pass header.from=<city domain> directly in a raw email. This code accepts that sender-supplied text as proof of authentication, then treats the reply as affiliated and lets it update a report’s public status and chat. Anyone able to address a valid reply-token mailbox can impersonate a jurisdiction contact.
How this was verified: A forged raw message received a passing verdict and produced public report effects.
This update joins a message to every matching delivered event without choosing one deterministically. When a message has both passing and failing delivery events, PostgreSQL can persist either value based on join order. This is a non-blocking data-quality concern, but it can make the admin inbox show an inaccurate authentication result and lead to incorrect operator review decisions.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of civfix/issue-tracker#138
What changed
On an event's member list, a person whose identity is hidden from you no longer carries the official CivFix check mark. Web and mobile.
Before you start
mainpushVerify
The official CivFix account cannot join an event or be blocked, so no screen can show it as a hidden member; "Not covered" says how it was checked.
Regression
A blocked person on an event's member list — [Web] [Mobile]
Not covered