Hi,
On our statuspage you can subscribe via email to any planned or unplanned outages. All works perfect!
However, if I enter an emailadres from someone else that is already subscribed, I can see their subscriptions and change them. At the moment there is no notification email send for changes on the subscriptions that you would like to receive. From an security perspective we would like to have a notification email send to the emailadres if there are any changes in the subscriptions. Is something like this possible?
E.g:
Attacker would like to know which services are used by company A. Looks online and finds an emailadres employee@companyA.com. This email adress is subscribed on the statuspage and the attacker sees all the subscriptions company A is subscribed to and can change/remove the subscriptions.
On save, a notfication email would be send to employee@companyA.com that there were changes in the subscriptions to notify them.
Hope something like this is possible.
Kind regards,
Bart.
Hey Bart,
Thanks for reaching out to Atlassian Community!
I understand that it's frustrating that anyone having a subscriber's email address can modify their subscription. It's a known issue and we are currently investigating how to implement a feature that would trigger a confirmation email to subscribers once their settings were changed. We don't have a timeframe on when to expect this to be implemented, but we'll make sure to send you and other affected users a notification about that. The ticket reference is STSPG-1963 - tracked internally.
Thanks a lot for your feedback and please let me know if there's anything else I can help you with.
Egor
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.