Good-Bids / goodbids

0 stars 0 forks source link

Emails without Admin access (or even User Accounts) can be confirmed as an NP’s Administration Email Address #939

Open jaspercroome opened 5 months ago

jaspercroome commented 5 months ago

As a site admin or super admin, I need to be able to validate that the email I'm adding as the Administration Email Address for a given NP site belongs to an active user, and that that user already has admin privileges.


Emails without Admin access (or even User Accounts) can be confirmed as an NP’s Administration Email Address

Here’s the Loom showing a non-Admin/non-User email address confirmed as Administration Email Address for an NP.

Luckily it was an existing Admin’s alternate email address that got added without a User account or confirmed Admin access, but we need to eliminate this possibility to prevent user errors that result in the wrong email addresses from getting main Admin notifications for NPs.

Return to main post.

linear[bot] commented 5 months ago
GOO-339 Discussion: anne_marie_cruz on 4/15/2024

**Emails without Admin access (or even User Accounts) can be confirmed as an NP’s Administration Email Address** Here’s the Loom showing [a non-Admin/non-User email address confirmed as Administration Email Address for an NP](https://www.loom.com/share/78bd2f3eadeb47afa188ae344d00d0f9). Luckily it was an existing Admin’s alternate email address that got added without a User account or confirmed Admin access, but we need to eliminate this possibility to prevent user errors that result in the wrong email addresses from getting main Admin notifications for NPs. Return to [main post](https://goodbids.discourse.group/t/draft-mode-urgent-admin-and-np-bdp-related-bugs-and-issues/747).

jaspercroome commented 5 months ago

I don't think this is an issue - the main site admin can be different from the users added to the site as admins. @clatwell , can you confirm? updated