hmis-tools / hmis-api-server

Version 2 of OpenHMIS
Mozilla Public License 2.0
15 stars 11 forks source link

Logged-in user should not be able to delete self via admin API. #64

Open kfogel opened 8 years ago

kfogel commented 8 years ago

One shouldn't be able to delete one's own user via API.

It's also questionable whether one should be able to remove admin rights on one's logged-in user who (by implication) has the admin rights needed to be able to remove admin rights.