private email account shouldn't be visible on a merge request
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Launchpad itself |
Triaged
|
High
|
Unassigned |
Bug Description
When someone request a merge of an account to his main account, the page "Merge request sent" show in clear the email of the account receiving this request, in this message: "An email message was sent to <email address hidden>. Please follow the instructions on that message to complete the merge. "
The problem here is when this account don't have a public email address, the person who asked the merge can have the email of this account just by requesting a merge.
How to reproduce:
- create a fake account with it's own email
- configure this fake account to have no public email address
- connect to launchpad with your main account
- request a merge of the fake account in your main account
tags: | added: code-review email privacy |
Changed in launchpad: | |
importance: | Undecided → High |
status: | New → Triaged |
tags: | removed: code-review |
Changed in launchpad: | |
assignee: | nobody → William Grant (wgrant) |
status: | Triaged → In Progress |
Changed in launchpad: | |
assignee: | William Grant (wgrant) → nobody |
status: | In Progress → Triaged |