some emails leak the email addresses of LP admins

Bug #1952623 reported by Junien F
12
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Launchpad itself
Fix Released
Critical
Jürgen Gmach

Bug Description

Hi,

The "mirror verification failed" emails are sent with LP admins and the mirror owner in the "To" field of the email, leaking the email addresses of all LP admins.

Could this please be changed to "Bcc" for the LP admins ? (or something more elaborate, I don't know).

Thanks !

Related branches

Revision history for this message
Junien F (axino) wrote :

Note that this also happens for translation errors emails, for a recent example :

Subject: Import problem - German (de) - bash in Ubuntu Jammy package "bash"

summary: - "mirror verification failed" emails leak the email addresses of LP
- admins
+ some emails leak the email addresses of LP admins
Revision history for this message
Colin Watson (cjwatson) wrote :

In the mirror verification case, as far as I can see, the mirror owner is notified in a separate email, so they wouldn't see the email addresses of LP admins. But I agree it seems best to avoid this anyway.

I think the simplest thing would be to send the notification as a separate email to each recipient in these cases. A useful thing to grep for would be `get_contact_email_addresses`; using the result of that directly as the To: line of a single email is fine when it's called with an ordinary user or maybe a team, but probably not if it's being called with some kind of distinguished admin team.

Jürgen Gmach (jugmac00)
Changed in launchpad:
status: New → Triaged
importance: Undecided → Critical
Jürgen Gmach (jugmac00)
Changed in launchpad:
assignee: nobody → Jürgen Gmach (jugmac00)
status: Triaged → In Progress
Jürgen Gmach (jugmac00)
Changed in launchpad:
status: In Progress → Fix Committed
Ioana Lasc (ilasc)
Changed in launchpad:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.