From e4d3e8637e68f4103e883ba518864cd2f99f5500 Mon Sep 17 00:00:00 2001 From: M66B Date: Thu, 19 Jan 2023 07:50:55 +0100 Subject: [PATCH] Insecure auto config over http --- app/src/extra/java/eu/faircode/email/Misc.java | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/app/src/extra/java/eu/faircode/email/Misc.java b/app/src/extra/java/eu/faircode/email/Misc.java index f83c8397b6..477fa17ffe 100644 --- a/app/src/extra/java/eu/faircode/email/Misc.java +++ b/app/src/extra/java/eu/faircode/email/Misc.java @@ -27,7 +27,9 @@ public class Misc { public static List getISPDBUrls(String domain, String email) { return Collections.unmodifiableList(Arrays.asList( "https://autoconfig." + domain + "/mail/config-v1.1.xml?emailaddress=" + email, - "https://" + domain + "/.well-known/autoconfig/mail/config-v1.1.xml?emailaddress=" + email + "https://" + domain + "/.well-known/autoconfig/mail/config-v1.1.xml?emailaddress=" + email, + "http://autoconfig." + domain + "/mail/config-v1.1.xml?emailaddress=" + email, + "http://" + domain + "/.well-known/autoconfig/mail/config-v1.1.xml?emailaddress=" + email )); } }