allow admin to delete/invalidate a user's 2-f device

Bug #911949 reported by Ricardo Kirkner
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Canonical SSO provider
Fix Released
High
Stuart Metcalfe

Bug Description

User story:

As a SSO admin, I want to be able to delete a 2nd factor device from a user's individual admin page so that I can respond quickly to reported loss/theft.

Details:

List all 2-f auth devices a user has registered in the user's account page in the admin, so that an administrator can easily remove or invalidate a device upon request by an user.

For deletion, a link/button should be available. For invalidation, a checkbox or status dropdown could be used.

Related branches

Changed in canonical-identity-provider:
importance: Undecided → Medium
status: New → Triaged
David Owen (dsowen)
tags: added: kb-feature sp-1
Changed in canonical-identity-provider:
milestone: none → 2-factor-internal-production-ready
David Owen (dsowen)
Changed in canonical-identity-provider:
importance: Medium → High
Revision history for this message
Stuart Metcalfe (stuartmetcalfe) wrote :

Adding an inline form to the account admin ui gives us add, edit and delete for free

Changed in canonical-identity-provider:
assignee: nobody → Stuart Metcalfe (stuartmetcalfe)
Revision history for this message
Stuart Metcalfe (stuartmetcalfe) wrote :

I've gone for deletion, not invalidation, as invalidation would (presumably) require a new db field.

Revision history for this message
Stuart Metcalfe (stuartmetcalfe) wrote :

Screenshot shows the proposed inline admin form

David Owen (dsowen)
Changed in canonical-identity-provider:
status: Triaged → In Progress
Changed in canonical-identity-provider:
status: In Progress → Fix Committed
Changed in canonical-identity-provider:
status: Fix Committed → Fix Released
David Owen (dsowen)
Changed in canonical-identity-provider:
status: Fix Released → Fix Committed
David Owen (dsowen)
Changed in canonical-identity-provider:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.