michaellaunay / alirpunkto

0 stars 0 forks source link

Restrict the access of users to their own data - with exception of those having rights to promote / demote users #91

Closed SergioArbarviro closed 1 month ago

SergioArbarviro commented 5 months ago

For reasons of security, a given user should by default only be allowed to view and modify his/her own data on the LDAP directory.

The only exceptions should be the users who have the specific rights to promote or demote the status of others, namely, as per Issues #56 and #57: