feat: Gravatar opt-in (off by default), configurable in Settings

Previously every account without a custom avatar automatically got
its email MD5-hashed and sent to gravatar.com at signup, with no way
to turn it off. Adds users.useGravatar (default false): removed the
automatic signup-time lookup entirely, and "remove photo" now falls
back to the initials placeholder instead of silently re-deriving a
Gravatar URL. New toggle in Settings -> Profile, off by default,
description explains the MD5-hash-to-third-party tradeoff. Existing
accounts' current avatarUrl is left untouched either way — no
retroactive avatar changes for anyone already using one.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Arnaud
2026-07-14 09:37:29 +02:00
parent 38516bff63
commit a08588cf85
14 changed files with 5132 additions and 14 deletions
+2
View File
@@ -1151,6 +1151,8 @@
},
"profile": "Profile",
"changePhoto": "Change photo",
"useGravatar": "Use Gravatar",
"useGravatarDescription": "Show a Gravatar photo when you haven't uploaded one — sends an MD5 hash of your email to gravatar.com. Off by default.",
"removePhoto": "Remove photo",
"avatarUploadSuccess": "Profile photo updated",
"avatarUploadFailed": "Failed to update profile photo",