Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add option to Unsubscribe via Unique URL in the Sent E-mail #15

Open
KimSJ opened this issue Sep 25, 2020 · 3 comments
Open

Add option to Unsubscribe via Unique URL in the Sent E-mail #15

KimSJ opened this issue Sep 25, 2020 · 3 comments
Labels

Comments

@KimSJ
Copy link

KimSJ commented Sep 25, 2020

The current architecture allows malicious unsubscribe. The solution adopted by mailchimp, for example, is to only allow unsubscribe via a link sent with every email, which contains a token which is used to verify authenticity. I'm not sure if this should be the only route to unsubscribe, but it should certainly be an option.

Presumably, the token should be fixed for a given user, so that the unsubscribe link works from any email. Although what happens if a naive user forwards a newsletter? I think one needs a "You have been unsubscribed, if this wasn't your intention, you can resubscribe by clicking this link" confirmation email, perhaps?

@KimSJ
Copy link
Author

KimSJ commented Sep 25, 2020

This approach does make it more verbose to do mass mailings, though. Can't see a way round that.

@saadmk11
Copy link
Owner

I actually prefer this way, but what you said totally makes sense. :) Need to look into it.

@KimSJ
Copy link
Author

KimSJ commented Sep 26, 2020

I can see that some people would prefer the current option, so I guess it needs to be a config parameter.

@saadmk11 saadmk11 changed the title Unsubscribe security Add option to Unsubscribe via Unique URL in the Sent E-mail Feb 4, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants