Profile API security #457
Labels
complexity: medium
Straightforward but some complexity (e.g., involves multiple files); will take 2-6 hours
ethan
milestone: missing
p-feature: user
ready for dev lead
role: dev
s: PD team
stakeholder: People Depot Team
size: 2pt
Can be done in 7-12 hours
Overview
As a security admin I want to make sure that users can see and update only appropriate fields. get for profile api should return all fields except password. Patch should allow all fields except password, created_at, updated_at, is_staff, is_superuser, and is_active.
Action Items
Technical
Recommended approach:
The text was updated successfully, but these errors were encountered: