?
avatar spinne1000
spinne1000
24 Jul 2017

Steps to reproduce the issue

Send a mass mail to all users from the backend menu Users -> Mass Mail Users.
Forgot to set "Recipients as BCC"

Expected result

The mail to the recipient should only contain the recipient himself in the "TO" field.

Actual result

All recipients are in the "TO" field.

System information (as much as possible)

Joomla! Version Joomla! 3.7.3 Stable [ Amani ] 4-July-2017 08:03 GMT

Additional comments

It would be best to set the defaults to an more save value like the "Recipients as BCC" and the group selection not to "All Users Groups" by default.

Votes

# of Users Experiencing Issue
1/1
Average Importance Score
5.00

avatar spinne1000 spinne1000 - open - 24 Jul 2017
avatar joomla-cms-bot joomla-cms-bot - labeled - 24 Jul 2017
avatar franz-wohlkoenig franz-wohlkoenig - change - 24 Jul 2017
Category com_mailto
avatar spinne1000
spinne1000 - comment - 24 Jul 2017

Why not sending ONE mail to EACH recipient only with one his address in the TO-field?


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/17223.

avatar brianteeman
brianteeman - comment - 24 Jul 2017

Because if you have thousands of users you might hit a server restriction on the number of emails you can send

avatar spinne1000
spinne1000 - comment - 24 Jul 2017

ok, I understand.
But is there not a problem with data privacy?
I think, here in Germany that is a problem. A site owner is not allowed to publish private data without the approval of the user. And with this settings in mass mail sending, I publish all email addresses to all users in the sending mails.


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/17223.

avatar brianteeman
brianteeman - comment - 24 Jul 2017

thats why there is the option to send as BCC

There is a case for making BCC enabled by default if someone wants to do a Pull Request to make that change

avatar spinne1000
spinne1000 - comment - 24 Jul 2017

If I go to "Users -> Mass Mail" Send as BCC is not enabled. I have to enable it each time.


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/17223.

avatar brianteeman
brianteeman - comment - 24 Jul 2017

That is why I said

There is a case for making BCC enabled by default if someone wants to do a Pull Request to make that change

avatar spinne1000
spinne1000 - comment - 24 Jul 2017

ok sorry. I missunderstood...
How to do that? :-) Is there a howto for new developers?


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/17223.

avatar franz-wohlkoenig franz-wohlkoenig - change - 25 Jul 2017
Status New Discussion
avatar brianteeman
brianteeman - comment - 27 Jul 2017

Actually it looks like it is a bug. The field is defined to be bcc by default but for some reason that isnt working

avatar markboos
markboos - comment - 29 Jul 2017

I would classify it as a bug, with security aspects. Recipients in the TO: field is a data leak. Think its not Low, because of the consequences.


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/17223.

avatar franz-wohlkoenig franz-wohlkoenig - change - 29 Jul 2017
Priority Low Medium
avatar franz-wohlkoenig
franz-wohlkoenig - comment - 29 Jul 2017

set it on "Medium".

avatar zero-24
zero-24 - comment - 29 Jul 2017

Please see #17336

avatar zero-24 zero-24 - change - 29 Jul 2017
Status Discussion Closed
Closed_Date 0000-00-00 00:00:00 2017-07-29 16:35:04
Closed_By zero-24
avatar zero-24 zero-24 - close - 29 Jul 2017

Add a Comment

Login with GitHub to post a comment