launchpad leaks private email addresses when sending mail
Bug #111147 reported by
Robert Collins
This bug affects 13 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Launchpad itself |
Invalid
|
Undecided
|
Unassigned |
Bug Description
affects /products/launchpad
affects /products/malone
When "Hide my email addresses from other Launchpad users" is enabled in the user preferences, launchpad still discloses the private addresses into sent emails.
They are contained in bug notification mail and comments, which are send out to other users and often even end up in public mailinglist archives!
Also the mails sent when contacting another LP user via his web contact form use the private email address.
Fixing this would just mean to anonymise source addresses in email
notifications etc., if the preference is set:
-> Replace the private address with the public bugnumber address / lp user name / contact URL.
Related branches
lp:~gmb/launchpad/dont-leak-email-addresses-bug-111147
Rejected
for merging
into
lp:launchpad
- Canonical Launchpad Engineering: Pending (code) requested
-
Diff: 726 lines (+138/-120)5 files modifiedlib/canonical/launchpad/mailnotification.py (+8/-28)
lib/lp/bugs/doc/bugnotification-email.txt (+14/-37)
lib/lp/bugs/doc/bugnotification-sending.txt (+65/-54)
lib/lp/bugs/scripts/bugnotification.py (+1/-1)
lib/lp/bugs/tests/test_bugnotification.py (+50/-0)
lp:~gmb/launchpad/dont-leak-private-email-addresses-bug-111147
- Deryck Hodge (community): Approve (code)
-
Diff: 313 lines (+47/-32)3 files modifiedlib/canonical/launchpad/mailnotification.py (+5/-0)
lib/lp/bugs/doc/bugnotification-email.txt (+10/-0)
lib/lp/bugs/doc/bugnotification-sending.txt (+32/-32)
Changed in malone: | |
importance: | Undecided → Low |
description: | updated |
summary: |
- no way to completely hide email address + launchpad leaks private email addresses |
tags: | added: story-better-bug-notification |
summary: |
- launchpad leaks private email addresses + launchpad leaks private email addresses when sending mail |
tags: | added: privacy |
Changed in malone: | |
importance: | Low → High |
Changed in malone: | |
assignee: | nobody → Graham Binns (gmb) |
milestone: | none → 10.06 |
Changed in malone: | |
status: | Triaged → In Progress |
tags: |
added: qa-ok removed: qa-needstesting |
Changed in malone: | |
status: | Fix Committed → Fix Released |
To post a comment you must log in.
There appears to be a column for this in the database (hide_email_ addresses) .