含'grant'的多邮箱Ajax表单提交出现403 Forbidden问题
多收件人邮件含'grant'邮箱触发403 Forbidden的解决方案
问题现象
发送多收件人邮件时,只要收件人列表包含含grant的邮箱(如grant@gmail.com),就会触发403 Forbidden错误;但单独给该邮箱发送邮件功能正常,排除该邮箱的多收件人发送也可正常执行。
相关Ajax提交代码
function trpMailingSend() { try { var e = $("#trpMailingSendForm").serializeArray(), t = new FormData; $.each(e, (function(e, n) { t.append(n.name, n.value) })), "" != $("#imageFileAdd").val() && (t.append("filePdf", $("#imageFileAdd")[0].files[0]), t.append("filePdfFile", $("#imageFileAdd")[0].files[0].name)), $.ajax({ type: "POST", url: '#APPLICATION.navigation.getURL("mailing", "trpMailingSend")#', data: t, dataType: "json", contentType: !1, cache: !1, processData: !1, error: function(e, t, n) { console.log(e), console.log(t), console.log(n), 403 === e.status ? (console.error("403 Forbidden: Access Denied"), "" !== e.responseText.trim() ? console.error("Response Text:", e.responseText) : console.error("Server did not provide additional information.")) : console.error("An error occurred:", n) }, success: function(e) { if ("1" == e.status) { showPopOver("{{There was an error sending emails. Our development team has been notified of the problem and will contact you when it is fixed.}}", "sendEmailBtn", '<DIV CLASS="group-btn text-center" STYLE="min-width:81px;"> <A CLASS="btn btn-danger btn-xs" ONCLICK="hidePopOver();">{{Ok}}</A> </DIV>') } else messageSystem.showMessage("{{E-mail(s) were sent successfully!}}", "4", "", "goPage('mailing', 'trpMailingInfo', " + e.data + ", '?ret=<CFIF isDefined(trpId)>1<CFELSE>2</CFIF>');"); console.log("test2"), console.log(e) } }) } catch (e) { console.error("An error occurred:", e) } }
可能原因
- 服务器安全拦截(WAF/防火墙):多数服务器会将
grant这类关键词识别为敏感词(关联权限授予类攻击特征),多收件人场景下,拼接的邮箱字符串更容易命中过滤规则;单独发送时因请求体结构、长度不同,未触发拦截。 - 邮件服务端规则限制:部分邮件服务商对特定关键词的收件人组合有过滤机制,不过单独发送正常的话,该概率较低。
- 请求参数格式问题:多收件人拼接格式是否符合服务器要求(如逗号分隔是否规范),但单独发送该邮箱正常,此可能性较低。
解决方案
1. 对敏感邮箱进行编码处理
在前端提交前,对含grant的邮箱进行URL编码或Base64编码,后端接收后解码。修改代码中参数处理逻辑:
$.each(e, (function(e, n) { let value = n.value; // 替换为实际的收件人字段名,比如"recipients" if (n.name === "recipients") { value = value.split(',').map(email => { const trimmedEmail = email.trim(); if (trimmedEmail.toLowerCase().includes('grant')) { return encodeURIComponent(trimmedEmail); // 若用Base64则替换为:btoa(trimmedEmail),后端对应解码 } return trimmedEmail; }).join(','); } t.append(n.name, value) }))
2. 排查服务器安全规则
联系服务器管理员,检查WAF/防火墙的拦截策略,确认是否存在针对grant关键词的过滤规则,可临时关闭规则测试,或添加该邮箱/请求路径至白名单。
3. 分批次发送邮件
将含grant的邮箱与其他收件人分开发送,前端自动处理流程:
// 拆分收件人列表 const rawRecipients = $("#recipients").val().split(',').map(email => email.trim()); const grantEmails = rawRecipients.filter(email => email.toLowerCase().includes('grant')); const normalEmails = rawRecipients.filter(email => !email.toLowerCase().includes('grant')); // 封装发送函数 function sendBatch(recipients) { var formData = new FormData; $("#trpMailingSendForm").serializeArray().forEach(item => { formData.append(item.name, item.name === "recipients" ? recipients.join(',') : item.value); }); if ($("#imageFileAdd").val()) { formData.append("filePdf", $("#imageFileAdd")[0].files[0]); formData.append("filePdfFile", $("#imageFileAdd")[0].files[0].name); } // 复用原Ajax逻辑 $.ajax({ type: "POST", url: '#APPLICATION.navigation.getURL("mailing", "trpMailingSend")#', data: formData, dataType: "json", contentType: false, cache: false, processData: false, error: function(e, t, n) { console.error("发送失败:", e.status, n); }, success: function(e) { if ("1" == e.status) { showPopOver("{{发送失败,已通知开发团队}}", "sendEmailBtn", '<DIV CLASS="group-btn text-center" STYLE="min-width:81px;"> <A CLASS="btn btn-danger btn-xs" ONCLICK="hidePopOver();">{{Ok}}</A> </DIV>') } else { messageSystem.showMessage("{{邮件发送成功!}}", "4", "", "goPage('mailing', 'trpMailingInfo', " + e.data + ", '?ret=<CFIF isDefined(trpId)>1<CFELSE>2</CFIF>');"); } } }); } // 分批次发送 if (grantEmails.length) sendBatch(grantEmails); if (normalEmails.length) sendBatch(normalEmails);
4. 检查邮件服务器日志
查看SMTP服务器或后端邮件服务的日志,获取403错误的具体原因,确认是否为邮件服务商的收件人过滤规则导致。
内容的提问来源于stack exchange,提问作者Sandeep Chaurasiya
相关产品推荐
相关产品推荐

