https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=11590

Blou <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |[email protected]

--- Comment #11 from Blou <[email protected]> ---
I'd like to reply on Robin's comment.

Here, I see a serious need for this as a matter of managing security.  Let just
call that the disgruntled employee scenario.  I have no need for it RIGHT NOW,
but as we plan for every possible outcome, to safeguard our customer's data or
maintaining 24/7 access, one of them is the I-QUIT-AND-DESTROY-ALL-YOUR-SH..
scenario.

So OK, I have my you-quit-I-lock-out-your-account.  But changing a database
password is a pain, always with some unforeseen consequences (yeah, I should
plan those too).  You try to not have to do it.  Life is just simpler that
way... Also, that's very hard to automate, or do manually through 100
databases.

SO, why give a user through a very easy to use UI, very easy to remember staff
url, an Uber-Access to all that is sacred in our business ?

Anyway, too long text.  We can argue about my failures as a security manager,
but I reserve the right to argue that this direct access to the system should
be blockable.

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list
[email protected]
http://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to