The Discussion

    From a security perspective, I don't like encouraging any workflow that would encourage a user to click on a link. See this here for more:

    Also, I'd like to understand the security model better. I want to make sure that an end user, simply by receiving a message, and viewing it within Outlook, will not cause a "confused deputy attack" (CSRF/XSS etc)

    Finally, is there a way to render an action message outside of Outlook? That is, I want to take your technology of formatting markup and hosting within javascript, and embed that within a bot (Facebook bot, iMessage, etc)

