As Designed IMG tag in email sent on new thread for subscribed nodes

Discussion in 'Resolved Bug Reports' started by cedivad, Mar 24, 2014.

  cedivad

    cedivad Active Member

    If the image proxy is enabled on ACP, the src of the image in the email should use the proxy as well.
  Chris D

    Chris D XenForo Developer Staff Member

    I think this is working correctly. I don't understand why you would want to proxy images that are embedded in emails.
  Mike

    Mike XenForo Developer Staff Member

    This is the correct behavior. The proxy is primarily designed around dealing with SSL issue and is specific to your site, so it explicitly blocks third party referrers for example. As such, it's not appropriate for emails.
  cedivad

    cedivad Active Member

    Let's suppose that 1000 users are subscribed to an important category. Email notifications.
    Anyone could add an image tag and get important informations out of those users.

    I understand that it's probably beyond paranoia for mosts of you.
    And yes, the limits on the image proxy referrers would be a problem.

    (everything on xenforo is as designed)
  Chris D

    Chris D XenForo Developer Staff Member

    I would argue that it would be down to the email client to protect their users from such things.

    Certainly Gmail uses some sort of image proxy itself so there would be no risk there.

