qanuj / elmah

Automatically exported from code.google.com/p/elmah
0 stars 0 forks source link

Limit email notification contents #141

Open GoogleCodeExporter opened 9 years ago

GoogleCodeExporter commented 9 years ago
What new or enhanced feature are you proposing?

Configure the email notification so as not to include sensitive information.

What goal would this enhancement help you achieve?

Emails sent out include the auth cookie for the request.  Replacing this in
your cookie allows you to impersonate the user.  Would like to use email
notices of error (with a link to elmah.axd?) but can't with this vulnerability.

Original issue reported on code.google.com by peter.fr...@gmail.com on 6 Nov 2009 at 9:05

GoogleCodeExporter commented 9 years ago

Original comment by azizatif on 7 Nov 2009 at 12:25

GoogleCodeExporter commented 9 years ago
This issue has been migrated to:
https://github.com/elmah/Elmah/issues/141
The conversation continues there.
DO NOT post any further comments to the issue tracker on Google Code as it is 
shutting down.
You can also just subscribe to the issue on GitHub to receive notifications of 
any further development.

Original comment by azizatif on 25 Aug 2015 at 8:18