Roundup Tracker - Issues

Issue 2551432

classification
Numeric local-part in emails causes username/ID mixups
Type: crash Severity: normal
Components: Web interface Versions:
process
Status: new
:
: : wilsj
Priority: :

Created on 2026-09-30 15:15 by wilsj, last changed 2026-09-30 15:15 by wilsj.

Messages
msg8534 Author: [hidden] (wilsj) Date: 2026-09-30 15:15
We have seen an influx of new Chinese `[0-9]+@qq.com` mailing our Roundup instance lately.

When mailgw creates a new user for one of these addresses, the username based on the local part 
becomes completely numerical. This in turn causes crashes when clicking the Submit button 
issue.item.html, as the values in `creator`, `nosy`, etc. are treated as IDs instead of numerical 
usernames:

  <class 'IndexError'>: no such user 123456789

Besides the crashing when trying to update an issue, there is also a risk that a user with an actual 
numerical ID matching the username already exists. I suspect such a scenario could result in all 
sorts of interesting recipient mixups.

I am aware of the existence of `try_id_parsing='no'`. Unfortunately, these cannot be set for 
properties that are built into the `IssueClass` type (such as `nosy`).

I see two possible solutions to this:

1. Modify mailgw's username generation to prefix the resulting numerical usernames with a letter.

2. Modify the template userauditors to add a letter to the username before inserting it into the 
database.

Before fixing this in our instance, I'd be curious to hear which, if any, of the proposed solutions 
would be preferred by upstream.
History
Date User Action Args
2026-09-30 15:15:31wilsjcreate