Bug 373313

Summary: Make From field in the composer read only
Product: [Applications] kmail2 Reporter: William L. Thomson Jr. <wlt-ml>
Component: composereditor-ngAssignee: Laurent Montel <montel>
Status: RESOLVED INTENTIONAL    
Severity: normal    
Priority: NOR    
Version: unspecified   
Target Milestone: ---   
Platform: Other   
OS: Linux   
Latest Commit: Version Fixed In:
Attachments: From email address replaced with another

Description William L. Thomson Jr. 2016-12-05 20:55:38 UTC
In newer versions of Kmail, the composer was changed so the From field is not editable. It does change when you change accounts/identities. But it also allows you to type in an email. Which I accidentally swapped a To address into From, and spoofed someones email. Really should not be able to use an email address without it being in an account. Or at minimum make it an option that can be turned on off. I almost never need to edit my email address, so being editable just makes such mistakes possible where they were not before.

Thank you for your consideration!
Comment 1 Laurent Montel 2016-12-06 06:21:48 UTC
it was never changed and we can change for sure.
Which is your kmail version ? 
could you paste a screenshot to show me where you want to change settings.
Thanks
Comment 2 William L. Thomson Jr. 2016-12-06 14:55:19 UTC
Created attachment 102648 [details]
From email address replaced with another

You can see in the attached image I can put what ever I want for the from address. I just copied and pasted your email from reply to bug email as an example. It is not part of my identity. I accidentally put a To address into From and spoofed an email I did not intend to because the field is editable. :)

kmail-16.08.3:5::gentoo 
Version 5.3.3 (QtWebEngine)
KDE Frameworks 5.28.0
Qt 5.7.0 (built against 5.7.0)
The xcb windowing system
Comment 3 Laurent Montel 2016-12-06 18:10:42 UTC
It's useful to make it editable.
But if it's a problem you can hide this lineedit by default.
I think it's the better solution.

I will not add a new option for this line :)


Regards
Comment 4 William L. Thomson Jr. 2016-12-06 18:55:21 UTC
I have hidden it. The only case it could be useful is in email spoofing. Which I do not think KDE would want to encourage that. I cannot see to many situations someone would want to compose an email in kmail using a different from address that was not associated with an account in kmail.

Either way, it is up to you all. I have hidden it now for myself so I cannot make such mistake on accident. But others may use it on purpose. I would think KDE to want to limit things that could be abused for bad purposes like spoofing emails.