View Issue Details

IDProjectCategoryView StatusLast Update
0006092SOGoWeb Address Bookpublic2025-02-14 08:58
Reporterkippels Assigned To 
PrioritynormalSeveritymajorReproducibilityalways
Status newResolutionopen 
Product Version5.8.0 
Summary0006092: Subscribing to shared address books can leak private data.
Description

I have two SOGoUserSources defined:

  • The first has no filter, canAuthenitcate=YES and isAddressBook = NO
  • the second one has a filter, canAuthenticate = NO and isAddressBook = YES

When I add a shared address book it is possible to leak all private mail addresses from the first defined SOGoUserSource.

Imo the isAddressBook-Setting should be respected here.

When I only have the first SOGoUserSource defined this behaviour also occurs.

Steps To Reproduce

Click "Address Book" -> "Subscriptions (+)" -> Start typing

Additional Information

I have attached two screenshots that illustrate this problem. The first one is a search in the global address book, the second one is a search in the add subscription box

TagsNo tags attached.

Activities

kippels

kippels

2025-02-14 08:58

reporter  

2025-02-14-09-38-33.png (39,165 bytes)   
2025-02-14-09-38-33.png (39,165 bytes)   
2025-02-14-09-39-08.png (50,776 bytes)   
2025-02-14-09-39-08.png (50,776 bytes)   

Issue History

Date Modified Username Field Change
2025-02-14 08:58 kippels New Issue
2025-02-14 08:58 kippels File Added: 2025-02-14-09-38-33.png
2025-02-14 08:58 kippels File Added: 2025-02-14-09-39-08.png