Activity log for bug #1082746

Date Who What changed Old value New value Message
2012-11-24 22:39:07 Mark Sapiro bug added bug
2012-11-24 22:49:56 Launchpad Janitor branch linked lp:mailman/2.2
2012-11-24 22:50:28 Launchpad Janitor branch linked lp:mailman/2.1
2012-11-24 22:52:35 Mark Sapiro mailman: status In Progress Fix Committed
2013-07-14 20:51:09 Mark Sapiro mailman: status Fix Committed Fix Released
2013-07-14 20:51:09 Mark Sapiro mailman: milestone 2.1.16 2.1.16rc1
2014-10-02 02:22:12 Mark Sapiro description There are discussions of this in threads at <http://mail.python.org/pipermail/mailman-users/2012-October/074213.html>, <http://mail.python.org/pipermail/mailman-users/2012-October/074278.html> and <http://mail.python.org/pipermail/mailman-users/2012-November/074412.html>. The Mailman developers do not think there is any way to prevent this other that disabling web subscribe entirely, as by definition, subscription requests come from unauthenticated users. However, an attempt will be made to mitigate this by making a site option to include a dynamically generated hidden hash in the subscribe form which will at least require an automated process to first GET and parse the listinfo form immediately prior to POSTing it. There are discussions of this in threads at <http://mail.python.org/pipermail/mailman-users/2012-October/074213.html>, <http://mail.python.org/pipermail/mailman-users/2012-October/074278.html> and <http://mail.python.org/pipermail/mailman-users/2012-November/074412.html> and a more recent thread at <https://mail.python.org/pipermail/mailman-users/2014-May/076880.html>. The Mailman developers do not think there is any way to prevent this other that disabling web subscribe entirely, as by definition, subscription requests come from unauthenticated users. However, an attempt will be made to mitigate this by making a site option to include a dynamically generated hidden hash in the subscribe form which will at least require an automated process to first GET and parse the listinfo form immediately prior to POSTing it.