Bug 533596

Summary: History page reveals all e-mail addresses
Product: [Community] Bugzilla Reporter: Daniel Qarras <dqarras>
Component: Bugzilla GeneralAssignee: PnT DevOps Devs <hss-ied-bugs>
Status: CLOSED NEXTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: low    
Version: 3.4   
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2010-01-08 21:27:54 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Daniel Qarras 2009-11-07 17:03:57 UTC
Description of problem:
When opening a bugzilla report without logging in e-mail addresses are hidded which is a good thing. However, when opening the History page for a bug report all e-mail addresses are shown in a valid format (like user).

To prevent spam bots sucking e-mail addresses those addresses should be hidden or obfuscated.

Version-Release number of selected component (if applicable):
Current Red Hat Bugzilla as of 2009-11-07

How reproducible:
Always

Steps to Reproduce:
1. See the description

Comment 1 David Lawrence 2009-11-09 19:39:55 UTC
This will be fixed in the next 3.4 release of Bugzilla coming soon to bugzilla.redhat.com.

Dave

Comment 2 David Lawrence 2010-01-06 21:28:43 UTC
We are getting ready to release our update to 3.4 this friday which may solve this problem. Can you please try the same action you are doing on bugzilla.redhat.com but on partner-bugzilla.redhat.com instead to see if it is still an issue?

Thanks

Comment 3 Daniel Qarras 2010-01-08 21:17:27 UTC
I can confirm that this issue is now fixed on partner-bugzilla.redhat.com.

Thanks!

Comment 4 David Lawrence 2010-01-08 21:27:54 UTC
Thanks for verifying