[Mailman-Developers] Viewing anyone's options w/o a password

Harald Meland Harald.Meland@usit.uio.no
01 Jul 1999 23:34:08 +0200


[Rob Francis]

> It seems kind of odd to me that if I know someone's email address on
> a list that I can go to the Info page and enter their email address,
> and then w/o a password see what options they have set.

I agree -- in principle this really is giving away more info than it
should, e.g. if I suspect that someone is subscribed to a list, I can
use this "feature" to verify my suspicion.

However, if we make access to the user options page password
restricted, we'd (obviously) have to put the "Email my password to me"
button on some other page -- and I sort of think the listinfo page is
crowded enough as it is.

> Just wondering if this was a decision made on purpose, or perhaps an
> oversight.

I don't know for sure, but I suspect it was done like this because of
the "Email my password to me" issue.

Good suggestions on how this should best be solved are welcome.
-- 
Harald