RocketChat / feature-requests

This repository is used to track Rocket.Chat feature requests and discussions. Click here to open a new feature request.
21 stars 9 forks source link

Improve "Export messages" security #496

Open emikolajczak opened 2 years ago

emikolajczak commented 2 years ago

Is your feature request related to a problem? Please describe. I propose improve "Export messages" security. Actually when you enable "Export messages" feature, by add role “Mail Messages”, you can send messages via email to any address which you provide in field To additional email. Also you can send to any user in system. It can lead to leak potentially sensitive data.

Describe the solution you'd like If is possible please add option when messages can be exported only to user who request it, hide fields To users and To additional emails. When export messages works as now, is not possible to use in corporate environment.

Describe alternatives you've considered Instead of send via email, attach exported messages as a messages with attachment in channel when export request were send.

Additional context image

emikolajczak commented 2 years ago

Related to https://github.com/RocketChat/Rocket.Chat/issues/19693

ankar84 commented 2 years ago

Agree with Emil! Email to asked without any additional email or just generate export messages archive and put it in same chat