【问题标题】:security of phpmailer for order confirmation emails用于订单确认电子邮件的 phpmailer 的安全性
【发布时间】:2020-01-05 01:44:48
【问题描述】:

我想知道使用 phpmailer 来确认我的电子邮件是否安全。

页面的顺序是这样的:

order_confirmation.php checkout_process.php(从技术上讲,用户看不到这是页面订单确认信息发送到/电子邮件发送给用户并将订单添加到数据库) checkout_success.php

在 checkout_process 页面上,虽然我正在更改发送电子邮件的方式以使用 phpmailer,因为我们看到交换服务器/gmail 帐户正在退回我们的电子邮件。

电子邮件现在可以正常工作,但我想知道在 checkout_process.php 页面上显示我们的服务器信息/密码是否安全:

   try {
        //Server settings
        $mail->SMTPDebug = false;                      // Enable verbose debug output
        $mail->isSMTP();                                            // Send using SMTP
        $mail->Host       = 'smtp.office365.com';                    // Set the SMTP server to send through
        $mail->SMTPAuth   = true;                                   // Enable SMTP authentication
        $mail->Username   = 'email@ourcompany.com';                     // SMTP username
        $mail->Password   = 'our actual password';                               // SMTP password
        $mail->SMTPSecure = PHPMailer::ENCRYPTION_STARTTLS;         // Enable TLS encryption; `PHPMailer::ENCRYPTION_SMTPS` also accepted
        $mail->Port       = 587;                                    // TCP port to connect to

        //Recipients
        $mail->setFrom('email@ourcompany.com', 'company name');
        $mail->addAddress($order->customer['email_address'], $order->customer['firstname']);     // Add a recipient
        $mail->addReplyTo('email@ourcompany.com', 'company');




        // Content
        $mail->isHTML(true);                                  // Set email format to HTML
        $mail->Subject = EMAIL_TEXT_SUBJECT;
        $mail->Body    = $email_order;
        $mail->AltBody = 'Your order with our company has shipped';

        $mail->send();
        echo 'order confirmation sent to order#:<br/>';
    } catch (Exception $e) {
        echo "Message could not be sent. Mailer Error: {$mail->ErrorInfo}";

【问题讨论】:

  • 1) 您的问题中缺少的一个细节是:“您在哪里运行此代码?”如果您在云中,大多数供应商都提供密钥保管库或秘密服务。有些提供服务帐户凭据。 2) 您的 PHP 邮件程序使用 TLS,这意味着电子邮件到邮件服务器的传输是安全的。但是,除非执行加密等额外步骤,否则电子邮件是传递机密或机密信息的不安全方法。

标签: php security office365 phpmailer


【解决方案1】:

为了使用任何邮件服务器,您必须提供秘密凭据,例如您的密码。这样做本身并不会使任何事情变得不安全。如果有人设法侵入您的服务器,他们可以看到这个文件和密码,但如果它存储在其他地方,他们可以按照这个文件将要获取的相同路径来获取它。 (例如,如果它以加密方式存储在数据库中,则此文件仍需要从黑客也可以访问的地方获取数据库凭据和解密密钥。)

也就是说,如果您的代码在某种代码存储库中(很可能是这样),那么 不 是包含密码的合适位置。除了入侵您的服务器之外,现在有人可以入侵您的存储库以获取密码。为避免此潜在问题,您的密码应存储在此文件可以引用的其他位置。这些天的常见做法是使用.env 文件来获取此类详细信息,该文件仅存在于服务器上,而不存在于任何存储库中。附带的好处是,无需修改代码即可轻松更改凭据(用于开发服务器等)。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2013-11-21
    • 1970-01-01
    • 1970-01-01
    • 2018-03-21
    • 2014-03-20
    • 1970-01-01
    相关资源
    最近更新 更多