•  
      request #42976 Clear sensitive information of deleted users
    Infos
    #42976
    Thomas Gerbet (tgerbet)
    2025-05-28 11:43
    2025-05-09 12:28
    44658
    Details
    Clear sensitive information of deleted users

    Tuleap should clear the password information of users with a deleted status. Users with a deleted status cannot be moved back to an active status so the password information will never used ever again. It is sensitive information Tuleap should not keep it.

    Globally Tuleap should not keep sensitive information like IP addresses once a user is marked as deleted.

    Authentication & LDAP
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-05-28
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-05-13 15:52
    • Summary
      -Clear password and access tokens of deleted users 
      +Clear sensitive information of deleted users 
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2025-05-13 15:07
    • Summary
      -Clear password of deleted users 
      +Clear password and access tokens of deleted users 
    • Status changed from Acknowledged to Under implementation