Profile API security #457
Labels
complexity: medium
ethan
milestone: missing
p-feature: user
role: dev
s: PD team
stakeholder: People Depot Team
size: 2pt
Can be done in 7-12 hours
Overview
As a security admin I want to make sure that users can see and update only appropriate fields. get for profile api should return all fields except password. Patch should allow all fields except password, created_at, updated_at, is_staff, is_superuser, and is_active.
Action Items
Technical
Recommended approach:
The text was updated successfully, but these errors were encountered: