Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

Server admins should be able to request 3PIDs for users #5497

Closed
rxl881 opened this issue Jun 19, 2019 · 4 comments
Closed

Server admins should be able to request 3PIDs for users #5497

rxl881 opened this issue Jun 19, 2019 · 4 comments
Assignees
Labels
A-Admin-API z-feature (Deprecated Label)

Comments

@rxl881
Copy link

rxl881 commented Jun 19, 2019

Currently 3PID mappings can only be requested (from Synapse or the identity server) by the related users (accounts). It would be very useful to open this up to server administrator accounts so that they can use the APIs to see registered user email addresses.

@rxl881 rxl881 added the z-feature (Deprecated Label) label Jun 19, 2019
@lampholder
Copy link
Member

I can't see any problem with this from a GDPR perspective, seeing as a server admin role is no different from a somebody with direct access to the database.

Obviously, anyone maintaining their own homeserver(s) or using a homeserver provided by a third party should employ information security best practice of 'least privilege' to ensure access to this API (and direct access to the db) is restricted to a minimal set of individuals.

@dklimpel
Copy link
Contributor

dklimpel commented Feb 3, 2020

see also: #6769

@dklimpel
Copy link
Contributor

IMO this is solved and can be closed.

@clokep
Copy link
Member

clokep commented Aug 20, 2021

I agree, looks like this is already possible!

@clokep clokep closed this as completed Aug 20, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
A-Admin-API z-feature (Deprecated Label)
Projects
None yet
Development

No branches or pull requests

5 participants