|Reported by:||anonymous||Owned by:||Jonas Borgström|
All e-mail addresses rendered by Trac must be masked. They cannot be simply placed in the page as is, as it's done today. In the current version it is just too easy for spam bots to catch all addresses in a Trac site.
On Tickets, the "Reported by" and "Cc" labels must be masked. The Wiki instead could provide a core Macro for that job. Probably there are even other points where addresses are rendered.
If the above is retained to not be the best way, any solution to not render the address directly is ok.
Maybe a note near e-mail related input fields saying "Your e-mail will be masked for protection against spam (what's this? (link))" is also a good idea, so users will be ok to included their addresses.
Please don't underestimate this problem. This is a critical issue that certainly needs a lot of attention.