Steps to replicate the issue (include links if applicable):
- Imagine you are presenting at a conference. You have to login to wikimedia for a demo.
- you login
- you hit EmailAuth (because of the conference IP) even though that never happened to you before.
- you get this:
- you might now have unintentionally revealed your email address to everyone at the conference.
What happens?:
Unintentional disclosure of private information
What should have happened instead?:
Show the emailaddress as: g**a@w****a.org
Software version (on Special:Version page; skip for WMF-hosted wikis like Wikipedia):
Other information (browser name/version, screenshots, etc.):
Relevant code: https://w.wiki/Dn99

