SFDO-Community / Summit-Events-App

Salesforce Event System developed at the University of St. Thomas
BSD 3-Clause "New" or "Revised" License
58 stars 55 forks source link

Microsoft Security Notice when trying to add calendar invite to outlook #547

Closed mcke0100 closed 5 months ago

mcke0100 commented 5 months ago

Describe the bug I just registered for the Finding Forward event and chose to add it to my Outlook calendar. I got this security issue, see below. I'm concerned there may be something going on with the Summit Events add to calendar feature that may be causing this. I was able to save on my phone using the Add to Apple Calendar link. There was no issue with that option. image

To Reproduce Steps to reproduce the behavior:

  1. Register for an event (internal to UST - Finding Forward Event)
  2. On the confirmation email, Click on the Add to Outlook Calendar link
  3. Warning is displayed
  4. Click Yes and continues on to process to add the event to my calendar

Expected behavior No error/warning would be given and the event would be added to my calendar

Screenshots attached above

Desktop (please complete the following information):

Additional context

tcdahlberg commented 5 months ago

@mcke0100, Not sure what the resolution to this is. Microsoft introduced it last month:

https://support.microsoft.com/en-us/office/outlook-prompts-security-notice-opening-ics-files-after-installing-protections-for-microsoft-outlook-information-disclosure-vulnerability-released-dec-12-2023-df8647ef-1828-421b-a266-79120b6190bd

mcke0100 commented 5 months ago

Thanks Thad.

From: Thaddaeus Dahlberg @.> Sent: Wednesday, January 24, 2024 10:18 AM To: SFDO-Community/Summit-Events-App @.> Cc: McKenna, Amy M. @.>; Mention @.> Subject: [External] Re: [SFDO-Community/Summit-Events-App] Microsoft Security Notice when trying to add calendar invite to outlook (Issue #547)

You don't often get email from @.**@.>. Learn why this is importanthttps://aka.ms/LearnAboutSenderIdentification

@mcke0100https://github.com/mcke0100, Not sure what the resolution to this is. Microsoft introduced it last month:

https://support.microsoft.com/en-us/office/outlook-prompts-security-notice-opening-ics-files-after-installing-protections-for-microsoft-outlook-information-disclosure-vulnerability-released-dec-12-2023-df8647ef-1828-421b-a266-79120b6190bd

- Reply to this email directly, view it on GitHubhttps://github.com/SFDO-Community/Summit-Events-App/issues/547#issuecomment-1908462701, or unsubscribehttps://github.com/notifications/unsubscribe-auth/BCEQ33V5PBV4HYYF2UD2KTTYQEX4XAVCNFSM6AAAAABCI76DQCVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMYTSMBYGQ3DENZQGE. You are receiving this because you were mentioned.Message ID: @.**@.>>

rdblake21 commented 5 months ago

Based on this, I'm going to close the issue with acknowledgement that this is a Microsoft update and not a current issue with Summit Events.