hasgeek / lastuser

Lastuser has been merged into Funnel. This repository is archived.
https://hasgeek.com/
BSD 2-Clause "Simplified" License
166 stars 30 forks source link

Email domain discovery weakness #192

Closed jace closed 7 years ago

jace commented 7 years ago

A user who has an email address at a particular domain (non-webmail only) can discover all other users with email addresses at that domain by creating an organization associated with that domain. This will add all those users as members.

This is currently not high impact (mostly gmail users), but could potentially be.

jace commented 7 years ago

The only obvious resolution to this issue is by reversing #108 and removing automatic team membership by domain. We may revisit this with a better solution in #185 with periodic verification.

jace commented 7 years ago

Fixed in 44d995e568320007ae3d28ec235765cb678244ce