History | Log In     View a printable version of the current page.  
Issue Details (XML | Word | Printable)

Key: OX-5880
Type: Improvement Improvement
Status: Needs Verification Needs Verification
Priority: Minor Minor
Assignee: Unassigned-Adserver
Reporter: Marcus Merz
Votes: 0
Watchers: 1

If you were logged in you would be able to see more operations.
OpenX Ad Server

The Return Path is not set in emails sent as reports and defaults to the user the webserver runs with.

Created: 13/Jan/10 04:04 PM   Updated: 13/Jan/10 04:06 PM
Component/s: OXP: Email System
Affects Version/s: OpenX 2.8.2
Fix Version/s: None
Security Level: Public (All users can see these issues)

Time Tracking:
Not Specified

Environment: OpenX v2.8.3 on Apache 2.2.13, PHP 5.2.9 und MySQL 5.0.45-

 Description  « Hide
When sending emails, OpenX does not explicitly set the Return-Path in the mail header. As such it defaults to the user which runs the webserver. This might have some privacy issues.

Easy fix in /lib/OA/Email.php:

In function sendMail() replace

$value = @mail($toParam, $subject, $contents, $headersParam);


$value = @mail($toParam, $subject, $contents, $headersParam, "-r" . $fromDetails['emailAddress']);

By setting the -r parameter, sendmail will set the Return-Path to the sender's email address ( From: ) as defined in OpenX.

Please note that this is just a hotfix. It should be tested that the address in the Return-Path (here: $fromDetails['emailAddress']) always defaults to the AdServer administrator's From: address and not to a client's/agencies email From: address when configuring OpenX with

"Use the owning account's Contact, Email and Name instead of the above Name, Email Address and Company when emailing reports to Advertiser or Website accounts."

i just did not search the sourcecode for any other variable available in EMail.php to take this into account as i do not use this setting.

 All   Comments   Work Log   Change History   FishEye   Crucible   Builds      Sort Order: Ascending order - Click to sort in descending order
There are no comments yet on this issue.