SoylentNews / slashcode

The slashcode repository for SoylentNews. The initial code base was uploaded as it appeared on Sourceforge as of the last commit in September 2009
http://soylentnews.org
GNU General Public License v2.0
44 stars 22 forks source link

Daily Site Stats Email - Privacy Leak #405

Closed juggs closed 9 years ago

juggs commented 9 years ago

The daily site stats email reveals new user email addresses.

Email subject: [SoylentNews] SoylentNews Stats for $date

Has a section titled "3 random users created yesterday:" which contains 3 usernames, their ID and their registered email address.

This section needs to be dropped in favour of a simple line that states "N new users created yesterday" - where N = number of new user accounts that day.

Email is insecure, we should not be transmitting users email addresses in this way.

paulej72 commented 9 years ago

Temp fix by removing the emails from the template in #413. Need to looking into replacing it with actual numbers.

paulej72 commented 9 years ago

This issue was moved to SoylentNews/rehash#153