[FIX] base: always send HELO when connecting SMTP
smtplib.SMTP API calls such as .sendmail() or .login() make sure on their first line that this command is sent, by calling .ehlo_or_helo_if_needed(). However, test_smtp_connection() does not use SMTP.sendmail() to simulate sending email, or the email would really be sent. Instead it uses the low-level API SMTP.mail() which does not make sure that HELO was sent. The connection test could be fixed by ensuring that this command was sent to the server in the test method. However, this could lead to inconsistent cases where the connection test passes whereas another usage in the code fails because the command was not sent. For example, someone could use the low-level API for some reason. EHLO could have already been sent because if authentication is enabled smtplib.SMTP.login() calls ehlo_or_helo_if_needed(). Therefore it is correct to call it ourselves at the end of our connect() method. STARTTLS sends a first EHLO, negociates the encryption, and leaves the state without the second EHLO, which should still be sent to the server, as stated by RFC 3207, in section "4.2 Result of the STARTTLS Command". https://www.ietf.org/rfc/rfc3207.txt closes odoo/odoo#34550 Signed-off-by: Julien Legros (jle) <jle@odoo.com>
This commit is contained in:
@@ -277,6 +277,11 @@ class IrMailServer(models.Model):
|
||||
smtp_user = pycompat.to_native(ustr(smtp_user))
|
||||
smtp_password = pycompat.to_native(ustr(smtp_password))
|
||||
connection.login(smtp_user, smtp_password)
|
||||
|
||||
# Some methods of SMTP don't check whether EHLO/HELO was sent.
|
||||
# Anyway, as it may have been sent by login(), all subsequent usages should consider this command as sent.
|
||||
connection.ehlo_or_helo_if_needed()
|
||||
|
||||
return connection
|
||||
|
||||
def build_email(self, email_from, email_to, subject, body, email_cc=None, email_bcc=None, reply_to=False,
|
||||
|
||||
Reference in New Issue
Block a user