Bug 373313 - Make From field in the composer read only
Summary: Make From field in the composer read only
Status: RESOLVED INTENTIONAL
Alias: None
Product: kmail2
Classification: Applications
Component: composereditor-ng (show other bugs)
Version: unspecified
Platform: Other Linux
: NOR normal
Target Milestone: ---
Assignee: Laurent Montel
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-12-05 20:55 UTC by William L. Thomson Jr.
Modified: 2016-12-06 18:55 UTC (History)
0 users

See Also:
Latest Commit:
Version Fixed In:


Attachments
From email address replaced with another (55.76 KB, image/png)
2016-12-06 14:55 UTC, William L. Thomson Jr.
Details

Note You need to log in before you can comment on or make changes to this bug.
Description William L. Thomson Jr. 2016-12-05 20:55:38 UTC
In newer versions of Kmail, the composer was changed so the From field is not editable. It does change when you change accounts/identities. But it also allows you to type in an email. Which I accidentally swapped a To address into From, and spoofed someones email. Really should not be able to use an email address without it being in an account. Or at minimum make it an option that can be turned on off. I almost never need to edit my email address, so being editable just makes such mistakes possible where they were not before.

Thank you for your consideration!
Comment 1 Laurent Montel 2016-12-06 06:21:48 UTC
it was never changed and we can change for sure.
Which is your kmail version ? 
could you paste a screenshot to show me where you want to change settings.
Thanks
Comment 2 William L. Thomson Jr. 2016-12-06 14:55:19 UTC
Created attachment 102648 [details]
From email address replaced with another

You can see in the attached image I can put what ever I want for the from address. I just copied and pasted your email from reply to bug email as an example. It is not part of my identity. I accidentally put a To address into From and spoofed an email I did not intend to because the field is editable. :)

kmail-16.08.3:5::gentoo 
Version 5.3.3 (QtWebEngine)
KDE Frameworks 5.28.0
Qt 5.7.0 (built against 5.7.0)
The xcb windowing system
Comment 3 Laurent Montel 2016-12-06 18:10:42 UTC
It's useful to make it editable.
But if it's a problem you can hide this lineedit by default.
I think it's the better solution.

I will not add a new option for this line :)


Regards
Comment 4 William L. Thomson Jr. 2016-12-06 18:55:21 UTC
I have hidden it. The only case it could be useful is in email spoofing. Which I do not think KDE would want to encourage that. I cannot see to many situations someone would want to compose an email in kmail using a different from address that was not associated with an account in kmail.

Either way, it is up to you all. I have hidden it now for myself so I cannot make such mistake on accident. But others may use it on purpose. I would think KDE to want to limit things that could be abused for bad purposes like spoofing emails.