Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • fusiondirectory fusiondirectory
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 35
    • Issues 35
    • List
    • Boards
    • Service Desk
    • Milestones
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Terraform modules
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar
  • fusiondirectoryfusiondirectory
  • fusiondirectoryfusiondirectory
  • Issues
  • #5397
Closed
Open
Issue created Feb 19, 2017 by bmortier@bmortierMaintainer

User is able to lock their own account

If a user has permission to view certain details of others' accounts (like for example allowing colleagues to share mobile numbers via the directory), and they have the permission to modify certain parts of their own information (ie via editowninfos), then they are able to lock their own account (which I do not want them to be able to do). Despite their being no specific permission granted to this property, a person is nonetheless able to affect it.

(from redmine: issue id 5397, created on 2017-02-19, closed on 2017-03-23)

  • Changesets:
    • Revision fc583418 by Côme Chilliet on 2017-03-13T10:06:17.000Z:
Fixes #5397 Use a separate ACL for account locking
  • Revision db40f923 by Côme Chilliet on 2017-03-23T09:24:02.000Z:
Fixes #5397 Use a separate ACL for account locking
  • Custom Fields:
    • Bug in version: 1.0.19
Assignee
Assign to
Time tracking