#5079 - Add additional admin session security / confirmation for sensitive member actions

  • By
  • Added
  • 5 views
Identifier #5079
Issue type Feature request or suggestion
Title Add additional admin session security / confirmation for sensitive member actions
Status Completed
Tags

Roadmap: v11 (custom)

Type: Security (custom)

Handling member Chris Graham
Addon core
Description There are a few actions for which I believe should have enhanced security (due to laws governing GDPR, privacy, and data breaches) / require a confirmed admin session regardless of the admin zone settings, namely actions that could either modify or leak potentially sensitive information about members:
* Editing a member's username, password, e-mail, phone number, or credit card information
* Deleting a member
* Deleting lurkers
* Merging a member (which involves deleting a member)
* Exporting members (especially since potentially sensitive information including hashed passwords are / can be included in the export)
* Running the Purge or Download action on privacy
* Any / all screens which display a member's IP address or other identifiable information
Steps to reproduce

Funded? No
The system will post a comment when this issue is modified (e.g., status changes). To be notified of this, click "Enable comment notifications".

Rating

Unrated