Escape return path extra params to php mail()
authorBrian Wolff <bawolff+wn@gmail.com>
Sat, 10 Dec 2016 13:03:21 +0000 (13:03 +0000)
committerBrian Wolff <bawolff+wn@gmail.com>
Sat, 10 Dec 2016 13:03:21 +0000 (13:03 +0000)
commitd2aba5a04ea17753eae7ab8b7ab049473147ff37
tree8e31a8dbf2812eb92c169ce5dd551281cad5d3f9
parenta3cb3cd362f70c6bc8e3cfee47ad5c6fa159c361
Escape return path extra params to php mail()

PHP only escapes some dangerous shell characters. This is a hardening
measure, as MW's sanitizeEmail routines should also have prevented
evil characters from being in mail addresses in the first place.

Bug: T152717
Change-Id: I3736d612ed40d257ee3dde8e98eb30ccf432670a
includes/mail/UserMailer.php