Skip to content
This repository has been archived by the owner on Nov 2, 2024. It is now read-only.

🐛 Don't show email addresses by default. #1011

Open
fnurkla opened this issue Apr 10, 2023 · 1 comment
Open

🐛 Don't show email addresses by default. #1011

fnurkla opened this issue Apr 10, 2023 · 1 comment
Labels
type: bug Something isn't working

Comments

@fnurkla
Copy link
Contributor

fnurkla commented Apr 10, 2023

Right now, all email addresses are shown in the open without any need of interaction or verification to see them. I find this a bad policy since it makes it easy for web crawlers to find our email addresses and sign them up for spam emails.

Steps to reproduce:

  1. Open dsek.se in a private window,
  2. click on the profile of any person that has posted a news item,
  3. see their email aliases without any verification,
  4. sign addresses up for spam email,
  5. profit.
@fnurkla fnurkla added the type: bug Something isn't working label Apr 10, 2023
@github-project-automation github-project-automation bot moved this to 🆕 New in DWWW 2023 Apr 10, 2023
@01ste02
Copy link
Collaborator

01ste02 commented Apr 12, 2023

I agree that this should not be publicly available. It might be a good idea to have the emails for a specific post visible, for example to have "root@dsek.se" listed under the post "root" on https://www.dsek.se/committees/km so that companies and outsiders can get in touch with us easily. However, it is not a good idea to list ALL emails that go to the person on their user profile without the client being signed in.

It is also not a good idea to list all aliases that go to, for example, root on https://www.dsek.se/committees/km as that might display emails for internal use that are not suitable to contact me through. I suggest that the committees should get to select which emails are displayed for each post, so that they can display their preferred address and not random irrelevant ones.

Another example: it is NOT appropriate to contact teknikfokusansvarig through kallelse@dsek.se, despite it being listed under https://www.dsek.se/committees/naru

EDIT: might also be a good idea to point out that all pages containing emails should be included in a robots.txt to blacklist them from being crawled.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
type: bug Something isn't working
Projects
No open projects
Status: 🆕 New
Development

No branches or pull requests

2 participants