diff website/issues/detectors/userauditor.py @ 4902:a403c29ffaf9

Security fix default user permissions Default user permissions should not include all user attributes. We now limit this to the username, realname and some further attributes depending on the schema. Note that we no longer include the email addresses, depending on your installation you may want to further restrict this or add some attributes like ``address`` and ``alternate_addresses``.
author Ralf Schlatterbeck <rsc@runtux.com>
date Fri, 04 Jul 2014 15:32:28 +0200
parents ad1a337cb5b7
children 35ea9b1efc14
line wrap: on
line diff

Roundup Issue Tracker: http://roundup-tracker.org/