Re: [issue2551089] pgp encrypt=yes, but password reset email is sent unencrypted
"John P. Rouillard" <[email protected]>
| Newsgroups | gmane.comp.bug-tracking.roundup.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi Thomas: In message <[email protected]>, Thomas Arendsen Hein writes: >When requesting a password reset via the web interface, the >reset email is sent unencrypted. The reset email is sent using mailer.py:Mailer::standard_message. This method doesn't send encrypted emails. The bounce_message method in the same class does support pgp encryption and may provide an outline of how to implement encryption. Maybe changing the signature to include crypt=False and implementing pgp encryption would work? I assume your concern is that the reset email url is available in plain text and could be used by a bad actor? >So far I haven't tested with newer Roundup versions. I did the analysis using 2.0.0 so password reset emails are still unencrypted. -- -- rouilj John Rouillard =========================================================================== My employers don't acknowledge my existence much less my opinions.