Socket
Socket
Sign inDemoInstall

pretix-ldap-mails

Package Overview
Dependencies
Maintainers
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

pretix-ldap-mails

Verify user supplied mails against LDAP


Maintainers
1

Pretix verify mails against ldap

This is a pretix plugin that can be used to verify the user provided mails against an ldap server. This does not verify the users password.
WARNING: This does verify that the user registering is the owner of the mail address.

Usage

  1. Install
  2. Configure in admin settings
  3. Enable the plugin for your event.

Security Conserns

Query

While we use a function of python-ldap to sanitize user input there might still be a possible exploit by inserting custom code into the ldap query. You should definitely use a read only user for ldap. User data should not be exposed as we do not print user data to the end user.

Brutforcing

Via a brutforcing attack this opens up the user to find valid mail adresses in your ldap. This is not different to a password reset feature telling you that it has (not) found an mail address.

FAQs


Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc