IQSS / IQSS/dataverse

Feature Request: Provide config param to prevent users from changing email address

Open
#11,720 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Type: Feature
Dominant language
Java
Stars
1.1k
Forks
564
Avg merge
2d 2h
Merged PRs (30d)
29

Description

Overview of the Feature Request

Provide a flag per dataverse installation that when set to true prevents all users from changing their email address.

What kind of user is the feature intended for?
(Example users roles: API User, Curator, Depositor, Guest, Superuser, Sysadmin)

All users but specifically end users (applicants, file downloaders, etc.)

What inspired the request?

At ADA, 98% of datasets are requested with the "guestbook-at-download" feature. The majority of these datasets require the applicant be from an academic or government institution (no social logins) to be approved for filedownload permissions.

So if an applicant logs in with an academic or government email address (and even verifies it), and is approved for a dataset, if they know they are leaving their position, they can change their email address to gmail (for example) or any other email address, and still have access after leaving their position = problematic.

What existing behavior do you want changed?

A user can change their email address in dataverse at any time.

Any brand new behavior do you want to add to Dataverse?

Provide a dataverse-installation-wide flag that when set to true, prevents all users from changing their email address.

When a user goes to another institution, they will have to re-apply for the data with their new email address, or negotiate with the data custodian to have their previously-approved datasets transferred to their new account (or have their 2 accounts merged).

Any open or closed issues related to this feature request?

Sort of related to #11719.

Are you thinking about creating a pull request for this feature?

No resources to do so.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are identified in the issue. Start by locating the account email-change flow and the installation-wide configuration options. Done means a Dataverse-wide flag prevents every user from changing their email address, with behavior covering the stated re-application or account-transfer scenario.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authentication, authorization
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.