Page MenuHomePhabricator

Document that disabling "metamta.one-mail-per-recipient" leaks recipients for "Must Encrypt"
ClosedPublic

Authored by epriestley on Feb 7 2018, 11:52 AM.
Tags
None
Referenced Files
F15472516: D19014.id45583.diff
Sat, Apr 5, 2:11 PM
F15461898: D19014.id45583.diff
Tue, Apr 1, 12:13 PM
F15436128: D19014.id.diff
Tue, Mar 25, 12:06 PM
F15433568: D19014.diff
Mon, Mar 24, 11:46 PM
F15424612: D19014.diff
Sat, Mar 22, 11:19 PM
F15393989: D19014.id45583.diff
Mar 15 2025, 11:18 PM
F15383956: D19014.id45610.diff
Mar 14 2025, 6:26 PM
F15371269: D19014.id45610.diff
Mar 12 2025, 12:05 PM
Subscribers
None

Details

Summary

Depends on D19013. Ref T13053. When mail is marked "Must Encrypt", we normally do not include recipient information.

However, when metamta.one-mail-per-recipient is disabled, the recipient list will leak in the "To" and "Cc" headers. This interaction is probably not very surprising, but document it explicitly for completeness.

(Also use "Mail messages" instead of "Mails".)

Test Plan

Read documentation in the "Config" application.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable