Sim
Well-known member
- Affected version
- v1.x and v2.x
I know this is as original designed - moderators have always been able to access user email addresses via the spam cleaner, but in a post-GDPR world, I'm not sure this is the best policy anymore.
While this is kind of a suggestion, I do feel that this is serious enough to warrant a "bug report" since it has privacy and legal implications and should really have been changed in the GDPR related releases we've had recently.
I wasn't actually aware that moderators could see user email addresses - indeed I was only alerted to it when one of my mods mentioned that he had Googled the email address of a new member and was concerned about what he found.
After an extensive search of my settings to work out what I had missed - I found a post here on xenforo.com which mentioned that mods can see the email via the spam cleaner.
The fact that he knew to use the spam cleaner to find the email address shows that it is a practice that has been going on for some time - there was no spam posted by this user, so no reason for the mod to be using the spam cleaner function for anything other than finding out information about the user.
Given that my moderators are not employees of my company and yet I am potentially liable for any actions they may take by using those email addresses, this is a serious issue with potential legal implications.
I need my moderators to be able to spam ban people, so disabling access to the spam cleaner is not an option. The moderators do NOT need to be able to see the user's email address to complete the task of spam banning someone.
We go to the trouble of hiding the email address from the moderators in all other parts of the UI, why should they necessarily have access to it in the spam cleaner?
I will be making template edits to hide email addresses from moderators in the UI to fix this for now - but I strongly believe that this should be a configurable option in the moderator permissions UI, something like:
This applies to both v1.x and 2.x
While this is kind of a suggestion, I do feel that this is serious enough to warrant a "bug report" since it has privacy and legal implications and should really have been changed in the GDPR related releases we've had recently.
I wasn't actually aware that moderators could see user email addresses - indeed I was only alerted to it when one of my mods mentioned that he had Googled the email address of a new member and was concerned about what he found.
After an extensive search of my settings to work out what I had missed - I found a post here on xenforo.com which mentioned that mods can see the email via the spam cleaner.
The fact that he knew to use the spam cleaner to find the email address shows that it is a practice that has been going on for some time - there was no spam posted by this user, so no reason for the mod to be using the spam cleaner function for anything other than finding out information about the user.
Given that my moderators are not employees of my company and yet I am potentially liable for any actions they may take by using those email addresses, this is a serious issue with potential legal implications.
I need my moderators to be able to spam ban people, so disabling access to the spam cleaner is not an option. The moderators do NOT need to be able to see the user's email address to complete the task of spam banning someone.
We go to the trouble of hiding the email address from the moderators in all other parts of the UI, why should they necessarily have access to it in the spam cleaner?
I will be making template edits to hide email addresses from moderators in the UI to fix this for now - but I strongly believe that this should be a configurable option in the moderator permissions UI, something like:
This applies to both v1.x and 2.x