#5442 - New notification type to let users know when staff SU'd into their account

  • By
  • Added
  • 9 views
Identifier #5442
Issue type Feature request or suggestion
Title New notification type to let users know when staff SU'd into their account
Status Closed (rejected)
Tags

Type: Legal compliance / Privacy (custom)

Handling member Deleted
Addon core_cns
Description We should add a new notification type that allows users to be notified when someone uses SU to gain access to their account.

Notification is enabled by default for all users via email and web notifications.

While I cannot 100% confirm, given the nature of the GDPR, I can reasonably assume this is something they would require. And even if they did not require this, I believe it is the ethical thing to do to implement such a feature for transparency; users have the right to know when staff access their account via SU especially considering actions done when under SU appear as that member.
Steps to reproduce

Additional information Be sure to document this in the core Privacy Policy hook as well.

Also, make sure the notification clearly documents what this means and that staff do NOT have the user's account credentials (it is a feature that the highest level of staff typically can do). And that if they believe the SU access was not warranted, they should contact (site email address) immediately. The notification should also tell the member who SU'd into their account.

Also also, a JavaScript confirmation box should appear when attempting to SU as a member warning of the implications of doing so (member will be notified, and SU is a tool that should never be used without just cause / for ill purposes such as to damage the reputation of members).

Make sure this works correctly when hard-coding "keep_su" in the URL as well.
Related to

#5848 - Increased consideration around SU feature

Funded? No
The system will post a comment when this issue is modified (e.g., status changes). To be notified of this, click "Enable comment notifications".

Rating

Unrated