Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Log when a site's email address is changed in wp-admin/options.php #90740

Open
arinoch opened this issue May 15, 2024 · 3 comments
Open

Log when a site's email address is changed in wp-admin/options.php #90740

arinoch opened this issue May 15, 2024 · 3 comments
Labels
[Feature Group] Site Settings & Tools Settings and tools for managing and configuring your site. [Feature] Site Settings All other general site settings. [Pri] High [Product] WordPress.com All features accessible on and related to WordPress.com. [Type] Feature Request Feature requests

Comments

@arinoch
Copy link

arinoch commented May 15, 2024

What

We should be logging as often as possible, and we do not log when a site's email address is modified from wp-admin/options.php. I'd like us to consider adding logging for this action.

Why

Specific features will use the blog admin email address as a fallback if the owner email address is unavailable, and it is possible to silently set this address to an address belonging to an unwitting third party. For context: p1715771406974199/1715767859.100399-slack-CDJ9Z349W

How

No response

@arinoch arinoch added [Feature] Site Settings All other general site settings. [Type] Feature Request Feature requests [Product] WordPress.com All features accessible on and related to WordPress.com. [Feature Group] Site Settings & Tools Settings and tools for managing and configuring your site. labels May 15, 2024
@mrfoxtalbot
Copy link

I know that @Automattic/explorers have been done some work towards syncing user information between dotcom and local (AT) sites.

Is this something that could be fixed by Explorers?

@allilevine
Copy link
Member

I know that @Automattic/explorers have been done some work towards syncing user information between dotcom and local (AT) sites.

Is this something that could be fixed by Explorers?

We have! This is somewhat related to Untangling since we're working in wp-admin, so I added it to the board.

How and why do users access this page?

@arinoch
Copy link
Author

arinoch commented May 17, 2024

How and why do users access this page?

The most common reason I see as an HE is for WooCommerce notifications. They send email to the admin email of the site, and users often want to redirect that to a different address. You can't change it in WooCommerce, so we often have them change it on this page.

In this specific case, however, it was Happiness needing to access this page for a user's site. Your context for that is in this internal thread. p1715771406974199/1715767859.100399-slack-CDJ9Z349W

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
[Feature Group] Site Settings & Tools Settings and tools for managing and configuring your site. [Feature] Site Settings All other general site settings. [Pri] High [Product] WordPress.com All features accessible on and related to WordPress.com. [Type] Feature Request Feature requests
Projects
Development

No branches or pull requests

3 participants