[Tickets #11376] Re: Itip auto-accept confirmation requests

bugs at horde.org bugs at horde.org
Sat Aug 25 16:16:47 UTC 2012


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/11376
------------------------------------------------------------------------------
  Ticket             | 11376
  Updated By         | Michael Rubinsky <mrubinsk at horde.org>
  Summary            | Itip auto-accept confirmation requests
  Queue              | IMP
  Version            | Git master
  Type               | Enhancement
  State              | Assigned
  Priority           | 1. Low
  Milestone          |
  Patch              |
-Owners             |
+Owners             | Horde Developers, Jan Schneider, Michael Rubinsky,
                     | Michael Slusarz
------------------------------------------------------------------------------


Michael Rubinsky <mrubinsk at horde.org> (2012-08-25 16:16) wrote:

I actually wanted to implement this in the ActiveSync code that  
handles invitations as well. I didn't do this for the same reason (and  
the fact that it wouldn't be consistent with what the user currently  
expects from using Horde). Exchange *does* do this, but, if I  
understand correctly, only for responses from "local" exchange users.

I would really like this feature though since it would complete our  
ActiveSync invitation support (making us the only FOSS groupware that  
supports this completely without relying on MAPI libraries).

What about making this a user controlled pref disabled by default and  
at least performing a check against the From header and the response's  
email field? IMO, it would be a low risk since the malicious user  
would need all of the event details, including the UID, right?





More information about the bugs mailing list