# Security/Privacy concern: Email exposed in DiscourseConnect Provider redirect URL

**URL:** https://meta.discourse.org/t/security-privacy-concern-email-exposed-in-discourseconnect-provider-redirect-url/397980
**Category:** Feature
**Tags:** pr-welcome
**Created:** [9 maart 2026 om 18:05 UTC](https://meta.discourse.org/t/security-privacy-concern-email-exposed-in-discourseconnect-provider-redirect-url/397980 "2026-03-09T18:05:25Z")
**Posts on this page:** 1
**Showing post:** 4

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [9 maart 2026 om 18:19 UTC](https://meta.discourse.org/t/security-privacy-concern-email-exposed-in-discourseconnect-provider-redirect-url/397980/4 "2026-03-09T18:19:28Z")

</div>

> [@JACK\_ZHANG](#):
>
> The core issue is: we don’t want to expose unnecessary user information (like email) to “third-party sites using Discourse for SSO login”. Users authorize only to prove “I am a legitimate user” - they don’t expect their email to be shared.

I’m curious, what is this downstream third party that has implemented our custom SSO protocol?

> [@JACK\_ZHANG](#):
>
> Would a site setting to control whether email is returned be acceptable?

I’d say that is #pr-welcome as long as it is not the default, so we don’t break existing sites.

---

_[View the full topic](https://meta.discourse.org/t/security-privacy-concern-email-exposed-in-discourseconnect-provider-redirect-url/397980)._
