plone / plone/plone.restapi

Possible massive spam with @email-notification endpoint

Open
#485 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

04 type: enhancement 05 type: question
Dominant language
Python
Stars
109
Forks
107
Avg merge
2d 3h
Merged PRs (30d)
4

Description

@email-notification endpoints does not require authentication on the client side so it could be used as an easy tool to spam the site owner in a public site.

A good option can be to implement a way to enable or disable this endpoint.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the @email-notification endpoint and its existing authentication and request-handling tests. Determine how site owners should enable or disable the endpoint and what response should be returned when it is disabled. Done means the endpoint can be controlled as specified and coverage verifies both enabled and disabled behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
api, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.