Skip to content

Unsubscribe links can be leaked in email replies

See example of this occurring here. I haven't pressed the unsubscribe button, but it looks like I could without logging in. I'd suggest forcibly stripping the GitLab footer from replies.

MR: https://dev.gitlab.org/gitlab/gitlabhq/merge_requests/2528

Edited by Victor Wu