Hidden primary email addresses can be viewed for most accounts on launchpad.net
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Launchpad itself |
New
|
Undecided
|
Unassigned |
Bug Description
It is currently possible to get the primary email address of (almost) any user on launchpad.net, even if the user sets his email address to private in his profile.
All that is needed is to visit the account merge page (https:/
https:/
The email address of <email address hidden> is shown when trying to merge, although it should NOT be visible to anyone. (see screenshot attached)
I was however NOT able to do this with the first (and only) other account I tried:
https:/
as a warning regarding private branches pops up, preventing a merge and thus not sending the request.
All that is needed to fix this is show the username instead of the email address when the request is sent.
information type: | Private Security → Public Security |