# Neatly decorated emails from watch, without compromising security

**URL:** <https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 19, 2016, 10:56am UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377 "2016-10-19T10:56:00Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![dan\_r](https://avatars.discourse-cdn.com/v4/letter/d/f14d63/32.png) [@dan\_r](https://discuss.elastic.co/u/dan_r)\
**Post date:** [October 19, 2016, 10:56am UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/1 "2016-10-19T10:56:00Z")

</div>

Hi

I want my email alerts to be more user-friendly.  
In order to do so, I made some styled email templates (with mustache expressions) using css. Unfortunately i can't paste them here.  
According to the [Watcher HTML Sanitization Documentation](https://www.elastic.co/guide/en/watcher/current/email-services.html#email-html-sanitization), **\_style** attributes are disabled in order to avoid XSS through CSS.  
This is reasonable, but i want to find a way to send really neatly decorated emails to my clients. My concern is not about what tags and attributes are supported by email clients (i have control on this in my case), but how to send formatted and user friendly mails safely.  
I am not really worried about XSS on client side, but mostly about XSS affecting the ELK environment.

Is it only a matter of allowing specific tags and attributes in a way that avoids XSS? or is there any built in solution in watcher for safly sending decorated mails?

Thanks  
Dan

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 20, 2016, 7:36am UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/2 "2016-10-20T07:36:57Z")

</div>

Hey,

did you enable the `_style` attributes and tried again? See the end of the [sanitization docs](https://www.elastic.co/guide/en/watcher/current/email-services.html#email-html-sanitization)

--Alex

---

<div class="post-metadata">

**Author:** ![JbRichardet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbrichardet/32/13197_2.png) [@JbRichardet](https://discuss.elastic.co/u/JbRichardet)\
**Post date:** [December 7, 2016, 5:37pm UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/3 "2016-12-07T17:37:30Z")

</div>

Hi @spinscale,

I tried adding

```
watcher.actions.email.html.sanitization: 
  allow: _styles

```

in my cloud config but I got an `Illegal user settings` error. Is it available on hosted ES?  
Thank you.

---

<div class="post-metadata">

**Author:** ![JbRichardet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbrichardet/32/13197_2.png) [@JbRichardet](https://discuss.elastic.co/u/JbRichardet)\
**Post date:** [December 7, 2016, 5:47pm UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/4 "2016-12-07T17:47:25Z")

</div>

Sorry, looks like it should be `xpack` now. I tried again with

```
xpack.notification.email.html.sanitization.allow: _tables, _blocks, _formatting, _links, _styles

```

but it failed too 😓. I'm using this on my self-hosted ES 5 and it works perfectly. Could you tell me what's illegal here?

Thanks.

Jb

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 8, 2016, 1:39pm UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/5 "2016-12-08T13:39:42Z")

</div>

Hey,

just to be sure, which version did you try on cloud so I can try to reproduce?

--Alex

---

<div class="post-metadata">

**Author:** ![JbRichardet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbrichardet/32/13197_2.png) [@JbRichardet](https://discuss.elastic.co/u/JbRichardet)\
**Post date:** [December 8, 2016, 1:49pm UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/6 "2016-12-08T13:49:24Z")

</div>

Hello,

I'm using 5.0.2 on both

---

<div class="post-metadata">

**Author:** ![JbRichardet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbrichardet/32/13197_2.png) [@JbRichardet](https://discuss.elastic.co/u/JbRichardet)\
**Post date:** [December 9, 2016, 1:24pm UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/7 "2016-12-09T13:24:45Z")

</div>

Did you manage to reproduce @spinscale?

I tried various combination of the settings but none worked.

---

<div class="post-metadata">

**Author:** ![igor\_k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_k/32/1157_2.png) [@igor\_k](https://discuss.elastic.co/u/igor_k)\
**Post date:** [December 9, 2016, 4:34pm UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/8 "2016-12-09T16:34:24Z")

</div>

Hi @JbRichardet,

We do not whitelist `xpack.notification.email.html.sanitization.allow` setting in Elastic Cloud hence it is illegal.

The reason is that we want to verify the ownership of the addresses that people send watches to. Having said that, your particular setting doesn't interfere with that as far as I can tell. We will discuss internally and decide if we want to allow setting this attribute for Cloud customers. Or if not then maybe we can whitelist it on your cluster.

I'll get back to you.

Thanks,  
Igor

---

<div class="post-metadata">

**Author:** ![JbRichardet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbrichardet/32/13197_2.png) [@JbRichardet](https://discuss.elastic.co/u/JbRichardet)\
**Post date:** [December 10, 2016, 12:01pm UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/9 "2016-12-10T12:01:46Z")

</div>

Thank you @igor_k !

I understand the security concerns, that's why I whitelisted all the recipients addresses in the UI 😉.

Let me know how it went!

Jean-Baptiste

---

<div class="post-metadata">

**Author:** ![igor\_k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_k/32/1157_2.png) [@igor\_k](https://discuss.elastic.co/u/igor_k)\
**Post date:** [December 11, 2016, 6:57pm UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/10 "2016-12-11T18:57:55Z")

</div>

@JbRichardet, a quick update: we've decided to whitelist these email sanitization settings, but it will take a few days to "do" this change and release it on all of our machines. In meantime, if you don't want to wait you can post the settings that you want to have applied here and list the cluster ids. I'll apply them and let you know and you won't be dependent on our release schedule 😉

Hope that works for you,  
Igor

---

<div class="post-metadata">

**Author:** ![JbRichardet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbrichardet/32/13197_2.png) [@JbRichardet](https://discuss.elastic.co/u/JbRichardet)\
**Post date:** [December 12, 2016, 9:26am UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/11 "2016-12-12T09:26:40Z")

</div>

Thank you @igor_k!

My setting is:

```
xpack.notification.email.html.sanitization.allow: _tables, _blocks, _formatting, _links, _styles

```

and my cluster is `1121ff` 🙂

---

<div class="post-metadata">

**Author:** ![igor\_k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_k/32/1157_2.png) [@igor\_k](https://discuss.elastic.co/u/igor_k)\
**Post date:** [December 12, 2016, 10:37am UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/12 "2016-12-12T10:37:45Z")

</div>

I've applied the change to your cluster, but it needs to create a new instance and replicate the data to it. This is needed for no downtime migration. I think it will take few more hours for the data to replicate. Stay tuned for updates!

Thanks,  
Igor

---

<div class="post-metadata">

**Author:** ![igor\_k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_k/32/1157_2.png) [@igor\_k](https://discuss.elastic.co/u/igor_k)\
**Post date:** [December 12, 2016, 3:19pm UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/13 "2016-12-12T15:19:17Z")

</div>

I see the cluster `1121ff` is updated, so these settings are applied:

```auto
xpack.notification.email.html.sanitization.allow: _tables, _blocks, _formatting, _links, _styles

```

Can you check if everything is fine on your end?

The way it works is that they are sticky and will be there even if you make a change to your cluster. If you want them changed or removed please let us know on the [cloud forum](https://discuss.elastic.co/c/cloud).

Thanks,  
Igor

---

<div class="post-metadata">

**Author:** ![JbRichardet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbrichardet/32/13197_2.png) [@JbRichardet](https://discuss.elastic.co/u/JbRichardet)\
**Post date:** [December 13, 2016, 10:07am UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/14 "2016-12-13T10:07:18Z")

</div>

My watch triggered this morning and styles were applied perfectly!

Thank you @igor_k

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/neatly-decorated-emails-from-watch-without-compromising-security/63377/15 "2017-07-06T13:42:07Z")

</div>


