Why does my web app allow company email addresses but not personal?

I had a slightly amusing bug yesterday. Our web app has a feature where you invite by email. I got a bug report stating that “I can invite emails from my company but not my personal email”. How strange. The service does not have any such filtering.

As part of the invitation a REST request is sent to the server in the form of /api/users/{email} . It works locally, but in Azure the endpoint was sometimes blocked. I found that the Azure Web Application Firewall had blocked the request due to OWASP CRS rules: “URL file extension blocked by policy”.

Let’s take a step back and look at the mail addresses:

  • Living in Sweden, a typical company address would be john@company.se
  • A typical personal email would be jane@gmail.com

Why would the firewall only block the latter one? Remember that in Windows, .com  files are executable and thus classified as dangerous. This of course has nothing to do with emails, but it is blocked by the default policy rules.

The personal vs company email was just an amusing interpretation of the situation :-)

And the solution? Instead of submitting the email as part of the URL, put it in the body or as a query parameter:

  • ❌: /api/users/jane@gmail.com
  • ✅: /api/users?email=jane@gmail.com
This entry was posted in Development and tagged , , , , , . Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *