Send Email Directly from JavaScript
emailjs.com
emailjs.com
So... a bold title saying something and then an explanation explicitly saying it was not true.
Essentially, this is a service which connects to different email accounts of your choosing - Yahoo, Outlook, Gmail etc. and then sends email via those.
I haven't tested it all the way, but in many scenarios when emails are sent via an application, the server essentially does the same thing, except that, IMHO, it takes a bit more knowhow.
In this case, you set up email services under your emailjs account one time and then everything is handled via Javascript on the front end via their servers.
Quite nice, come to think of it.
Except the privacy aspect, of course!
When we set up it up like this on our servers, the only parties that can read it are the recipients, the service provider and us. In this case, emailjs also gets to have a look at the emails.
Do they ask for your email account password? It should really be a token authorization but I doubt personal email providers allow this sharing use case.
For example, Stripe offers a client-only integration with similar limitations - the product catalog must be defined within the stripe dashboard. https://stripe.com/docs/payments/checkout/client
At https://clerk.dev (disc: founder), we do all of sign up, sign in, and user profile management from just the client. We’re able to keep it secure because we also do session/cookie management, so can tell who is signed in.
Emailjs has an interesting concept here. It’s definitely on-trend, though I personally wouldn’t like users being able to trigger emails to other users, which seems possible today (correct me if I’m wrong?)
Have you considered an option to require a signed JWT with requests, which could contain the user’s email address? That would make it so users can only trigger spam to themselves (except in cases of xss), but retain a mostly client-only experience. (Generating the jwt requires a backend, but developers may already have one available if they’re using another service like Hasura that follows a similar pattern.)
On the client side, unless you want to authorize spam sent from your account to any recipient of an attacker’s choosing, you can only use this service to send emails to fixed recipients, so most use cases of transactional email (e.g. user authentication, notification, marketing) are out of question. Sending emails on behalf of users to yourself on a contact page is the sole use case I can think of, but that market is crowded as is with more focused and less confusing offerings. Any other use cases I missed?
Indeed, someone could copy your code, but they will only be able to send your templates, with your content, and will not be able to send a custom email with their own content (spam). Which is absolutely not interesting for attackers.
E.g. sending verification emails from the client is a bit hare-brained, as I can just as easily steal the verification link from the dev console…
> All email services require some sort of authentication to send the emails on your behalf. That makes it a really bad idea to use them directly from client-side – revealing your password or your secret keys will allow anyone to send emails on your behalf.
EmailJS keeps your authentication details on the server-side, and the client-side code just triggers a predefined email template, similarly to how any client-server application is working.
also,
> Additionally, we've also developed various tools to prevent abuse – for instance, we have IP based rate limits to prevent bots from spamming, the whitelist of origin, and also support reCAPTCHA tests to make sure that a human is sending the email (although it's up to the developer to turn this feature on).
Given that EmailJS doesn't send email directly - it only sends through the accounts (e.g. Gmail) you've connected - this feels like a recipe for getting your email account shut down rapidly. If your template allows a variable destination (i.e. you can set To: from client-side) and there's enough latitude in the template, I don't see anything stopping people spamming through this service beyond the "abuse measures" like IP rate limiting.
> Personal email services allow connecting personal email providers that offer basic email functionality – an email address and an inbox. These include providers like Gmail, Fastmail, Outlook 365, etc'. Personal email services are useful in EmailJS when you need to send a small number of emails to yourself, or need to send emails to other people from your personal email account. Note, your personal email account could be blocked if you go over the daily limit of the email provider, and your email address could be flagged as spam if you send unsolicited emails to multiple recipients. Our general recommendation is to use personal email services only for development purposes or for very low volume usage.
Source: https://www.emailjs.com/docs/tutorial/adding-email-service/
The real risk is that someone finds this script on your website, open, and abuses it for themselves. Which is exactly what spammers already do, from the old sendmail.pl scripts to current vulnerable Wordpress extensions. If an external actor finds this and abuses it, that will be a world of pain.
Worse, if someone was specifically trying to target you for some hurt, the ability to send emails they control directly from your personal account?! There is so much damage you could do with that ability..
Seems like you need to use a template field to modify the ‘to’ field, but that would still require you to pass the template value in the request.
I have one site that is generated by Gatsby that could conceivably use this instead of the php script I currently have setup to handle the contact form.