Skip to content
Snippets Groups Projects
Commit a6dd5745 authored by Andreas Ellewsen's avatar Andreas Ellewsen Committed by Jonas Braathen
Browse files

Add flag to prevent nin verification in frontend

If a sponsor verifies a nin that is already in use by an account in
cerebrum, the guest will gain access to that account, which in turn
allows the guest to change the password of that account. This makes it
possible to abuse the guest service to steal the account of users.

A feature that checks for this problem, and helps the sponsor make a
decision on it, will be introduced in the near future. At that point
nin verification can be enabled again.

Resolves: GREG-202
parent f9aca19d
No related branches found
No related tags found
1 merge request!275Add flag to prevent nin verification in frontend
Pipeline #114887 passed
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment