Skip to content

Email notification settings API returns the stored SMTP password - #5981

Merged
ramonsmits merged 1 commit into
release-6.21from
backport-5e2364f-to-6.21
Oct 9, 2026
Merged

ramonsmits merged 1 commit into
release-6.21from
backport-5e2364f-to-6.21

Conversation

@ramonsmits

@ramonsmits ramonsmits commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

GET /api/notifications/email returned the stored SMTP password to every
caller that can read the settings. This includes the reader role and, with
authentication disabled (the default), anonymous callers.

The password is now write-only:

- GET never returns it.
- A save with an empty password keeps the stored password. ServicePulse
  sends its form back without a password, because it no longer receives
  one.
- A save without an account removes the stored password.

Tests:

- NotificationsControllerTests (unit) cover the GET response and how each
  kind of save changes the stored password.
- One acceptance test checks the HTTP response end to end.

(cherry picked from commit 5e2364f)
@ramonsmits
ramonsmits merged commit c264408 into release-6.21 Oct 9, 2026
36 checks passed
@ramonsmits
ramonsmits deleted the backport-5e2364f-to-6.21 branch October 9, 2026 14:24
@ramonsmits ramonsmits changed the title Do not return the SMTP password from the notifications API Email notification settings API returns the stored SMTP password Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants