It appears that src.fedoraproject.org is not configured to handle email. I attempted to reply to a pull request email notification (which has a Reply-To: of xyx...@src.fedoraproject.org). I can see the message sitting in the outbound queue of my mail server, failing with: connect to src.fedoraproject.org[209.132.181.15]:25: Connection refused
It seems that there isn't an MX specified for src.fedoraproject.org and there isn't a mail server running on that host.
We probibly need to discuss this. It's correct that we have this disabled currently. Normally this functionality works with issues, and I wasn't even aware it could work with PRs.
Enabling it will open src.fedoraproject.org to a larger security footprint.
If we decide to not enable it, can we add something to the PR's to indicate that replies must be via the web interface?
@puiterwijk and @pingou Thoughts? and/or we can discuss at the next meeting...
Metadata Update from @kevin: - Issue priority set to: Next Meeting (was: Needs Review)
At the bottom of notifications coming from pagure.io you can see:
To reply, visit the link below or just reply to this email https://pagure.io/fedora-infrastructure/issue/7082
The last part "or just reply to this email" is missing on notifications coming from src.fp.o, in purpose :)
Imho, the reply-to header should be removed as well when there is no milter configured (so that's an upstream bug for me).
Pierre
We probibly need to discuss this. It's correct that we have this disabled currently. Normally this functionality works with issues, and I wasn't even aware it could work with PRs. Enabling it will open src.fedoraproject.org to a larger security footprint. If we decide to not enable it, can we add something to the PR's to indicate that replies must be via the web interface? @puiterwijk and @pingou Thoughts? and/or we can discuss at the next meeting...
I filed https://pagure.io/pagure/issue/3399 upstream for removing the Reply-To. As far as I'm concerned this issue can be closed, then. Email would be nice, but I realize it does open up a whole can of security worms.
Metadata Update from @kevin: - Issue close_status updated to: Upstream - Issue status updated to: Closed (was: Open)