NeonGeckoCom / neon-hana

HTTP Access to DIANA deployed services
Other
0 stars 0 forks source link

Default disable email service with note in docs explaining rationale #4

Closed NeonDaniel closed 10 months ago

NeonDaniel commented 10 months ago

Description

This adds an option to disable the email service because anyone with access to the API would be able to send an email from the configured email address with any attachments/email contents

Issues

Other Notes

The email proxy service should do some kind of validation of email contents to prevent abuse, but it must allow for skills to reasonably use the email service. Consider also imposing stricter rate limits as emails are sent infrequently under normal circumstances