ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Email Address Issue

    Scheduled Pinned Locked Moved IT Discussion
    53 Posts 7 Posters 12.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Alex Sage @scottalanmiller
      last edited by

      @scottalanmiller I can't. but I am not logged in.....

      view-source:https://community.nodebb.org/topic/8776/nodebb-email-exposure-bug

      1 Reply Last reply Reply Quote 0
      • tonyshowoffT
        tonyshowoff
        last edited by

        My guess is that they need the email address to generate the gravatar, but they should generate the hash before pushing to the frontend.

        1 Reply Last reply Reply Quote 0
        • A
          Alex Sage
          last edited by

          Yeah. Sadly I can't seem to reproduce the problem on there site.

          tonyshowoffT 1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller @Alex Sage
            last edited by

            @aaronstuder said in Mangolassi is leaking everyone's email address!:

            @scottalanmiller Is there a way to fix it for now? Disable a plugin maybe? or do we have to wait?

            Well we just disabled Gravatar. If that was it, it's gone. Check now.

            1 Reply Last reply Reply Quote 0
            • tonyshowoffT
              tonyshowoff @Alex Sage
              last edited by

              @aaronstuder said in Mangolassi is leaking everyone's email address!:

              Yeah. Sadly I can't seem to reproduce the problem on there site.

              They appear to be pre-generating the page, probably some sort of caching, my guess is they do not have a vanilla install.

              scottalanmillerS 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                If Gravatar wasn't it, I'm not sure where to look next.

                tonyshowoffT 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @tonyshowoff
                  last edited by

                  @tonyshowoff said in Mangolassi is leaking everyone's email address!:

                  @aaronstuder said in Mangolassi is leaking everyone's email address!:

                  Yeah. Sadly I can't seem to reproduce the problem on there site.

                  They appear to be pre-generating the page, probably some sort of caching, my guess is they do not have a vanilla install.

                  They run newer code at the very least. And they do a few different things because they use it for testing.

                  1 Reply Last reply Reply Quote 0
                  • tonyshowoffT
                    tonyshowoff @scottalanmiller
                    last edited by

                    @scottalanmiller said in Mangolassi is leaking everyone's email address!:

                    If Gravatar wasn't it, I'm not sure where to look next.

                    Did not fix it, it's sent regardless, so re-enable it so people can seem my kickass gravatar.

                    1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller
                      last edited by

                      Gravatars seem to be cached somehow. I'm still seeing them even though the plugin was removed.

                      A 2 Replies Last reply Reply Quote 0
                      • A
                        Alex Sage
                        last edited by

                        I notice emoji's work on there site too........

                        scottalanmillerS A 2 Replies Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller
                          last edited by

                          Are you seeing them disappear?

                          1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Alex Sage
                            last edited by

                            @aaronstuder said in Mangolassi is leaking everyone's email address!:

                            I notice emoji's work on there site too........

                            That's always been known. They work for Jared, too.

                            1 Reply Last reply Reply Quote 0
                            • A
                              Alex Sage @scottalanmiller
                              last edited by Alex Sage

                              This post is deleted!
                              1 Reply Last reply Reply Quote 0
                              • A
                                Alex Sage @Alex Sage
                                last edited by Alex Sage

                                This post is deleted!
                                1 Reply Last reply Reply Quote 0
                                • A
                                  Alex Sage @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in Mangolassi is leaking everyone's email address!:

                                  Gravatars seem to be cached somehow. I'm still seeing them even though the plugin was removed.

                                  Cloudflare?

                                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @Alex Sage
                                    last edited by

                                    @aaronstuder said in Mangolassi is leaking everyone's email address!:

                                    @scottalanmiller said in Mangolassi is leaking everyone's email address!:

                                    Gravatars seem to be cached somehow. I'm still seeing them even though the plugin was removed.

                                    Cloudflare?

                                    Doesn't even see that that could be possible. What technology would allow that to happen?

                                    A 1 Reply Last reply Reply Quote 0
                                    • A
                                      Alex Sage @scottalanmiller
                                      last edited by

                                      @scottalanmiller https://support.cloudflare.com/hc/en-us/articles/200169556-How-can-I-tell-if-CloudFlare-is-caching-my-site-or-a-specific-file-

                                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @Alex Sage
                                        last edited by

                                        @aaronstuder said in Mangolassi is leaking everyone's email address!:

                                        @scottalanmiller https://support.cloudflare.com/hc/en-us/articles/200169556-How-can-I-tell-if-CloudFlare-is-caching-my-site-or-a-specific-file-

                                        How is that related? We are talking about dynamic content. It cannot be cached by a caching service. you could not see the posts if that were the case.

                                        1 Reply Last reply Reply Quote 1
                                        • scottalanmillerS
                                          scottalanmiller
                                          last edited by

                                          We got it.... it appears to be something wrong with NodeBB, reload was saying that it worked but failing. Did a full forced restart and it appaers to have dropped Gravatar.

                                          Check now on the emails.

                                          1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller
                                            last edited by

                                            Looks like that cleaned up the stupid issue with the notifications too. We removed that plugin a month ago.

                                            tonyshowoffT 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 2 / 3
                                            • First post
                                              Last post