View Issue Details

IDProjectCategoryView StatusLast Update
0006119SOGoWeb Mailpublic2025-05-03 15:36
ReporterNeustradamus Assigned Toqhivert  
PriorityhighSeveritymajorReproducibilityalways
Status assignedResolutionopen 
Product Version5.12.1 
Summary0006119: Remove e-mail address or username from interface link to be more secure?
Description

Dear SOGo team,

It is possible to remove the email address or username from interface link to be more secure?

Some examples with sogo1, sogo2, sogo3 accounts:

Thanks in advance.

Regards,

Neustradamus

Steps To Reproduce

Open SOGo and look the https link.

TagsNo tags attached.

Activities

qhivert

qhivert

2025-05-03 11:51

administrator   ~0018202

Hello, yes, you can do that.
Check the part "Hide mail in website url" there -> https://www.sogo.nu/news/2024/sogo-v5100-released.html
After restarting sogo, you will also need to restart your memcached server and expire all current session with the command sogo-tool expire-sessions 0

Note that the dav url won't be changed, though. We made that choice to keep all previous caldav configuration still operational.

Neustradamus

Neustradamus

2025-05-03 14:49

reporter   ~0018203

@qhivert: Thanks for your answer but it is not enabled by default and badly it is not perfect.

On https://www.sogo.nu/news/2024/sogo-v5100-released.html:


Hide mail in website url

SOGo website use your email in its url like this:

To do that set those parameters in your sogo.conf:
SOGoURLEncryptionEnabled = YES;
SOGoURLEncryptionPassphrase = "16_chars_secrets";


But there is always an IDENTIFIER, my request is to have nothing instead of email address or username (identifier too).

Some examples with sogo1, sogo2, sogo3 accounts (second solution is perfect):

Can you solve it completely?

Thanks in advance.

qhivert

qhivert

2025-05-03 15:34

administrator   ~0018204

Last edited: 2025-05-03 15:36

Not for the current version, it would need a complete rework.
The good news is we are doing the next version from scratch and it won't have any id in the url -> https://www.sogo.nu/news/2025/fosdem-and-future-of-sogo.html

Issue History

Date Modified Username Field Change
2025-05-02 16:23 Neustradamus New Issue
2025-05-03 11:51 qhivert Note Added: 0018202
2025-05-03 11:51 qhivert Assigned To => qhivert
2025-05-03 11:51 qhivert Status new => feedback
2025-05-03 14:49 Neustradamus Note Added: 0018203
2025-05-03 14:49 Neustradamus Status feedback => assigned
2025-05-03 15:34 qhivert Note Added: 0018204
2025-05-03 15:36 qhivert Note Edited: 0018204