-
Notifications
You must be signed in to change notification settings - Fork 687
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
We should not allow journalist username deleted
#5232
Comments
Good point, we should have a disallowed list of usernames and disallow the creation of new usernames with that. Of course there can be existing users that have this username so we can keep that in mind for client development, but we can distinguish legitimate users with the username |
@kushaldas @redshiftzero I would like to work on this. |
@prateekj117 Go for it! Please find us on https://gitter.im/freedomofpress/securedrop if we can help you get started on this -- you can also come join our standups Monday-Thursday at 4PM UTC here https://meet.google.com/ekb-kkhf-mrk (they're announced on Gitter). |
@eloquence Sure. |
@eloquence I am confused why |
Probably original design decisions like this were motivated by wanting to ensure a minimum amount of historical data on the system in case of theft/seizure. Having records of when accounts were added/deleted seems pretty innocuous, but you never know. |
@zenmonkeykstop @redshiftzero Hmm, I agree. Though, why don't we just have a |
Ok, it must be that way, because even after deletion person can be personally identified if we keep a separate |
Because in #5178 we are now marking
deleted
as the name/uuid of any journalist account which is deleted from the system, we should not allow the termdeleted
as the journalist name (via the web interface). I think this will help in reducing confusion in future.The text was updated successfully, but these errors were encountered: