From 1b47d4bc0e7eb9dd2d24e232008cc2771b7b11a1 Mon Sep 17 00:00:00 2001 From: Brendan Heywood Date: Fri, 16 Oct 2020 18:09:35 +1100 Subject: [PATCH] MDL-69513 email: Add support for email DKIM signatures --- admin/classes/form/testoutgoingmailconf_form.php | 2 +- admin/settings/server.php | 9 +++++++++ lang/en/admin.php | 4 ++++ lib/moodlelib.php | 13 +++++++++++++ lib/upgrade.txt | 1 + 5 files changed, 28 insertions(+), 1 deletion(-) diff --git a/admin/classes/form/testoutgoingmailconf_form.php b/admin/classes/form/testoutgoingmailconf_form.php index fbf8ac4fb1c..f344cfea587 100644 --- a/admin/classes/form/testoutgoingmailconf_form.php +++ b/admin/classes/form/testoutgoingmailconf_form.php @@ -43,7 +43,7 @@ class testoutgoingmailconf_form extends \moodleform { $mform = $this->_form; // Recipient. - $options = ['maxlength' => '100', 'size' => '25']; + $options = ['maxlength' => '100', 'size' => '25', 'autocomplete' => 'email']; $mform->addElement('text', 'recipient', get_string('testoutgoingmailconf_toemail', 'admin'), $options); $mform->setType('recipient', PARAM_EMAIL); $mform->addRule('recipient', get_string('required'), 'required'); diff --git a/admin/settings/server.php b/admin/settings/server.php index cb586b4017b..71376aa9fdc 100644 --- a/admin/settings/server.php +++ b/admin/settings/server.php @@ -455,6 +455,15 @@ if ($hassiteconfig) { new lang_string('divertallemailsexcept_desc', 'admin'), '', PARAM_RAW, '50', '4')); + $noreplyaddress = isset($CFG->noreplyaddress) ? $CFG->noreplyaddress : 'noreply@example.com'; + $dkimdomain = substr(strrchr($noreplyaddress, "@"), 1); + $dkimselector = empty($CFG->emaildkimselector) ? '[selector]' : $CFG->emaildkimselector; + $pempath = "{$CFG->dataroot}/dkim/{$dkimdomain}/{$dkimselector}.private"; + $temp->add(new admin_setting_heading('emaildkim', new lang_string('emaildkim', 'admin'), + new lang_string('emaildkiminfo', 'admin', ['path' => $pempath, 'docs' => \get_docs_url('Mail_configuration#DKIM')]))); + $temp->add(new admin_setting_configtext('emaildkimselector', new lang_string('emaildkimselector', 'admin'), + new lang_string('configemaildkimselector', 'admin'), '', PARAM_FILE)); + $url = new moodle_url('/admin/testoutgoingmailconf.php'); $link = html_writer::link($url, get_string('testoutgoingmailconf', 'admin')); $temp->add(new admin_setting_heading('testoutgoinmailc', new lang_string('testoutgoingmailconf', 'admin'), diff --git a/lang/en/admin.php b/lang/en/admin.php index 455a2cd0a2f..1f0b57c4671 100644 --- a/lang/en/admin.php +++ b/lang/en/admin.php @@ -231,6 +231,7 @@ $string['configemailchangeconfirmation'] = 'Require an email confirmation step w $string['configemailfromvia'] = 'Add via information in the "From" section of outgoing email. This informs the recipient from where this email came from and also helps combat recipients accidentally replying to no-reply email addresses.'; $string['configemailsubjectprefix'] = 'Text to be prefixed to the subject line of all outgoing mail.'; $string['configemailheaders'] = 'Raw email headers to be added verbatim to all outgoing email.'; +$string['configemaildkimselector'] = 'The DKIM selector is arbitrary and your DNS record(s) must match this.'; $string['configenablecalendarexport'] = 'Enable exporting or subscribing to calendars.'; $string['configenablecomments'] = 'Enable comments'; $string['configenablecourserequests'] = 'If enabled, users with the capability to request new courses (moodle/course:request) will have the option to request a course. This capability is not allowed for any of the default roles. It may be applied in the system or category context.'; @@ -529,6 +530,9 @@ $string['editorspelling'] = 'Editor spelling'; $string['editorspellinghelp'] = 'Enable or disable spell-checking. When enabled, aspell must be installed on the server.'; $string['editstrings'] = 'Edit words or phrases'; $string['emailchangeconfirmation'] = 'Email change confirmation'; +$string['emaildkim'] = 'DKIM email signing'; +$string['emaildkimselector'] = 'DKIM selector'; +$string['emaildkiminfo'] = 'If both the DKIM selector is set and a private certificate file is found which matches the emails From domain in sitedata/dkim/[domain]/[selector].private then the email will be signed. In most cases (ie if allowedemaildomains is empty) then only a single certificate is needed in: {$a->path}. For more setup details see {$a->docs}.'; $string['emailfromvia'] = 'Email via information'; $string['emailheaders'] = 'Email headers'; $string['emailsubjectprefix'] = 'Email subject prefix text'; diff --git a/lib/moodlelib.php b/lib/moodlelib.php index 8634bfb2382..6e68d0113ee 100644 --- a/lib/moodlelib.php +++ b/lib/moodlelib.php @@ -6384,6 +6384,19 @@ function email_to_user($user, $from, $subject, $messagetext, $messagehtml = '', $mail->addReplyTo($values[0], $values[1]); } + if (!empty($CFG->emaildkimselector)) { + $domain = substr(strrchr($mail->From, "@"), 1); + $pempath = "{$CFG->dataroot}/dkim/{$domain}/{$CFG->emaildkimselector}.private"; + if (file_exists($pempath)) { + $mail->DKIM_domain = $domain; + $mail->DKIM_private = $pempath; + $mail->DKIM_selector = $CFG->emaildkimselector; + $mail->DKIM_identity = $mail->From; + } else { + debugging("Email DKIM selector chosen due to {$mail->From} but no certificate found at $pempath", DEBUG_DEVELOPER); + } + } + if ($mail->send()) { set_send_count($user); if (!empty($mail->SMTPDebug)) { diff --git a/lib/upgrade.txt b/lib/upgrade.txt index 2d2536ecad7..d2095bac2b2 100644 --- a/lib/upgrade.txt +++ b/lib/upgrade.txt @@ -56,6 +56,7 @@ information provided here is intended especially for developers. a callback to be provided to determine whether page can be accessed. * New setting $CFG->localtempdir overrides which defaults to sys_get_temp_dir() * Function redirect() now emits a line of backtrace into the X-Redirect-By header when debugging is on +* Add support for email DKIM signatures via $CFG->emaildkimselector === 3.9 === * Following function has been deprecated, please use \core\task\manager::run_from_cli().