private email account shouldn't be visible on a merge request

Bug #1098309 reported by YoBoY
22
This bug affects 3 people
Affects Status Importance Assigned to Milestone
Launchpad itself
Triaged
High
Unassigned

Bug Description

When someone request a merge of an account to his main account, the page "Merge request sent" show in clear the email of the account receiving this request, in this message: "An email message was sent to <email address hidden>. Please follow the instructions on that message to complete the merge. "

The problem here is when this account don't have a public email address, the person who asked the merge can have the email of this account just by requesting a merge.

How to reproduce:
 - create a fake account with it's own email
 - configure this fake account to have no public email address
 - connect to launchpad with your main account
 - request a merge of the fake account in your main account

Tags: email privacy
Revision history for this message
YoBoY (yoboy-leguesh) wrote :
Curtis Hovey (sinzui)
tags: added: code-review email privacy
Changed in launchpad:
importance: Undecided → High
status: New → Triaged
William Grant (wgrant)
tags: removed: code-review
William Grant (wgrant)
Changed in launchpad:
assignee: nobody → William Grant (wgrant)
status: Triaged → In Progress
William Grant (wgrant)
Changed in launchpad:
assignee: William Grant (wgrant) → nobody
status: In Progress → Triaged
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.