savannah-hackers
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[sr #110592] Privacy: Please don't include IP and UserAgent in email hea


From: INVALID.NOREPLY
Subject: [sr #110592] Privacy: Please don't include IP and UserAgent in email headers
Date: Sat, 1 Jan 2022 22:17:15 -0500 (EST)
User-agent: Mozilla/5.0 (X11; Linux aarch64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36

Follow-up Comment #4, sr #110592 (project administration):

I don't see a point in the whole "# User details." block.

If the savannah frontend has been used to create spam in the past it should be
catched before actually sending the mail (limiting notifications for new
users, denying them to add mail addresses to CC or similar).
Adding some kind of personal data identifiers from the sender so recipients
can filter spam based on those seems somewhat backwards to me.

As a side note:
I don't remember if PHP allows \n in $_SERVER['HTTP_USER_AGENT'] but if yes
everybody could inject their own mail headers into the notification mails and
possibly replace the body by adding two \n in a row.

    _______________________________________________________

Reply to this item at:

  <https://savannah.nongnu.org/support/?110592>

_______________________________________________
  Message sent via Savannah
  https://savannah.nongnu.org/




reply via email to

[Prev in Thread] Current Thread [Next in Thread]