[Dovecot] was dove 1.2 %%u expands only to % SETACL: Unknown command partly solved more info

Robert Schetterer robert at schetterer.org
Fri Jan 16 01:40:42 EET 2009


Hi Timo,

Timo Sirainen schrieb:
> On Thu, 2009-01-15 at 14:49 +0100, Robert Schetterer wrote:
>>> i guess the % is produced fom thunderbird
>>>
>>> here tbs raw in log
> ..
>>> with telnet this does not happen
> 
> So if you copy&paste all the Thunderbird's commands to a telnet session,
> it doesn't log the % error?

didnt tried that, but i have tested horde/imp and mulberry as clients
and they dont produce such error in the log
normally i would say it some kind of TB special

> 
>>> my first tests were with listescape enabled
>>> without any additionional listescape config
>>> and leads to false interpreted the . in the username domainpart
>>> ( guess this has to be config stuff in listescape i didnt have done yet
>>> perhaps you have examples)
> 
> There isn't any need for extra configuration. But yes, you're right, I
> do see it breaking:
> 
> * LIST (\Noselect \HasChildren) "/" "shared/domain.org/tss at domain.org"
> * LIST (\HasNoChildren) "/" "shared/domain/org/tss at domain/org/Trash"
> 
> I'll try to get that fixed.

that would be nice cause listescape might be needed with usernames
having dot in their names

> 
>> with horde imp there is no wrong % expansion  in dovecots log so it
>> seems clear that this is an thunderbird issue
> 
> It still shouldn't happen and I'm not able to reproduce it.

hm...? dont know what to say, it not urgent for me
as long as it only produces log entries and all other stuff
i need works, perhaps i should setup a fresh install in vmware
cause all the testing may brake something, and see if it apears again

> 
>> after all whats missing is quota listing for shared folders
>> ( dont know if you might implement this easily in the quota code )
>> it should be there in my mind , cause transactions with shared
>> folders i.e copy maybe fail by overload quota of a shared folder
>> for now user has no chance ( until he has no imap debug etc) to find out
>> why i.e copy might fail in his client, with shown quota he might be able
>> to find out that there is less space left in the shared folder to i.e
>> copy a mail to it.

> 
> I'm not really sure about this. The code already exists to see other
> users' quota, but I'm just worried that it could be thought of as a
> security hole / privacy leak. If copying fails the client will get a
> "Out of quota" error, isn't that enough?

for sure out of quota should be enough, but you know how users are
i see the question rising why a quota from shared folders cant be seen
it looks imcomplete, but if it would uprise security holes
forget it, or code it later , there is much more to do
which is more importend.
Its great to see shared folders and imap acl working in dovecot
cause your now going to be alternative to cyrus, this is what i searched
ever


-- 
Best Regards

MfG Robert Schetterer

Germany/Munich/Bavaria


More information about the dovecot mailing list