[openstreetmap/openstreetmap-website] User account self-deletion allows bad actors to delete and recreate the same account name to "lose" changeset discussion and block history (Issue #4018)

SomeoneElseOSM notifications at github.com
Wed May 3 08:32:36 UTC 2023


> We could save a hash instead.

That's not really relevant to the main problem here.  Let's not worry about any general issues around account name re-use for now and just concentrate on preventing blocked users from deleting their accounts themselves.  They'll still be able to ask; they just won't be able to do it themselves.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/openstreetmap/openstreetmap-website/issues/4018#issuecomment-1532643909
You are receiving this because you are subscribed to this thread.

Message ID: <openstreetmap/openstreetmap-website/issues/4018/1532643909 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstreetmap.org/pipermail/rails-dev/attachments/20230503/9a34f4fb/attachment.htm>


More information about the rails-dev mailing list