Closed (works as designed)
Project:
Easy Email
Version:
3.0.4
Component:
Email Overrides
Priority:
Normal
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
22 Oct 2025 at 13:30 UTC
Updated:
22 Oct 2025 at 13:35 UTC
Jump to comment: Most recent
Comments
Comment #2
zengenuity commentedSecurity-related token evaluations are not saved in the log. If someone had access to create emails but not administer users, they could use the password reset functionality and email log to take control of other users' accounts. So, we purposely don't allow this.
Tokens that aren't security-related are replaced before being stored in the log. The list of "unsafe" tokens is in the code here: https://git.drupalcode.org/project/easy_email/-/blob/3.0.6/src/Service/E...