Good morning,
today I stepped into a strange but huge problem.
I modified a document into confluence. This document contained an HTML table with LOTS OF PRIVATE DATA. I also configured a mail server, to send notifications about that project.
This morning, my collegue received the HTML table via mail, IN CLEAR WITHOUT REQUESTING PASSWORD. That means that if someone intercepted my message, could read the WHOLE MESSAGE WITHOUT CREDENTIALS.
Is this the default behavior? Is this, in your opinion, something acceptable in an on premise solution?
I am very disappointed, this costed me a lot of time and money to recover from this situation.
Now I have unconfigured the mail server, but what I was expecting was that if you sent a notification, you will send A SIMPLE LINK, WITH AN INTERNAL ADDRESS, WHICH WILL REQUEST USER AND PASSWORD TO SEE THE MODIFICATION! NOT A CLEAR HTML TABLE AS CONTENT OF THE EMAIL! THIS HAS NO SENSE AT ALL!