Overview
Actions done by email (creation/update) are, by design, unsecure as there is no guarranty that sender can be spoofed. The only possibility to make it secure is to GPG sign a message.
This feature will requires:
- One configuration option at site admin to activate or not the feature (disabled and marked as unsecured by default)
- On configuration option at tracker admin level to activate or not the feature (some trackers my not be as sensitive as other)
- Identify/mark/taint artifacts created this way in case of future audit (email headers should be stored)
- only siteadmin can see those information