bcgov / tfrs

Transportation Fuels Reporting System
Apache License 2.0
23 stars 40 forks source link

TFRS - Audit of IDIR admin access #2903

Closed Grulin closed 2 weeks ago

Grulin commented 1 month ago

Describe the task Perform an audit of admin access in TFRS to limit risk of too many users having access to admin functions.

Change Historical Data Entry to be accessible to only Admin users.

Purpose There are too many people with access to admin privilege within the TFRS application. This presents a security risk because the admin role on the IDIR side has a substantial amount of power to change things within TFRS. This should be better monitored on an ongoing basis and user set-up and inactivation should be regulated.

Acceptance Criteria

Additional context