Make e-mail address on Person unique #570
Labels
No labels
Security
TeX
auto-update
board
done
board
ready
board
todo
check
delete-eslint-rc-js
check
update-builddeps-package-json
check
update-eslint-rc-js
check
update-gitignore
check
update-merge-request-template
check
update-prettier-ignore
check
update-pyproject-toml
check
update-renovate-json
check
update-tox-ini
part
backend
part
ci
part
docs
part
frontend
part
i18n
part
non-technical
part
packaging
prio
1
prio
2
prio
3
release-mr-5.x
size
large
size
medium
size
small
source
customer
source
customer::fsmw
source
customer::fss
source
customer::teckids
source
downstream
type
breaking
type
bug
type
feature
type
refactoring
workflow
blocked
workflow
confirmed
workflow
current-todo
workflow
discussing
workflow
new-app
workflow
wontfix
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
aleksis/AlekSIS-Core#570
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The e-mail address field should be unique, also for perosns, and we should prohibit the use of e-mail addresses for multiple persons.
Re-using e-mail addresses is a security issue because it simplifies account hijacking scenarios.
Alternatively, we could ensure that for all account-related features, e.g. OpenID claims, the mai laddress from the linked use is used, and only enforce uniqueness for user mail addresses.
assigned to @yuha
assigned to @nik and unassigned @yuha
unassigned @nik
@lukasw Is there a reason why you removed all labels?
No, must have been accidentally
assigned to @hansegucker
mentioned in merge request !3014
mentioned in commit
bce3137596