Currently the module decrypts user email addresses when a user is loaded in dbee_entity_load(). While this covers a lot of scenarios in which user information is accessed, it doesn't cover every situation.

For example, when core sends out the user activation or user blocked emails the encrypted email addresses get returned and the emails fail to send as a result. User module sends out those notifications from _user_mail_notify() which is called from postSave() in the User class to send the emails. In that scenario the user object is passed to _user_mail_notify() which then accesses the email address with getEmail() on the user account, but the encrypted value is returned.

I've found one way of fixing this is to override getEmail() in the User class to always make sure that dbee_decrypt() is called. I'm not sure if this is too heavy handed, but it would seem to me that with this module in place you would need to make sure that method calls dbee_decrypt() to ensure the actual address is returned at all times.

Patch to follow.

Comments

jeni_dc created an issue. See original summary.

jeni_dc’s picture

Status: Active » Needs review
StatusFileSize
new905 bytes

Adding patch.

  • thedut committed 4955785 on 8.x-2.x authored by jeni_dc
    Issue #2977302 by jeni_dc: User email addresses not always decrypted
    
thedut’s picture

Status: Needs review » Fixed

Thanks a lot. Commited to dev version !

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.