datasektionen / hodis

User lookup and information management system
https://hodis.datasektionen.se
0 stars 0 forks source link

Disallow users from updating their own stuff #18

Closed foodelevator closed 11 months ago

foodelevator commented 11 months ago

The frontend in zfinger doesn't even seem to provide the login token so updating one's year doesn't even work anymore. Apparently anyone can currently updates one's information (except ugkthid and kthid, but including tag & names), which I have been told should be possible.

With the recent addition, this also includes membership status, which people should definitely not be able to decide for one self.

Until those changes people's names were sometimes reset due to searches that hit kth:s ldap. That was apparently just a temporary thing since 2018 that I removed so now people can decide what their names and emails should be.