Comment 4 for bug 942979

Revision history for this message
Tres Henry (tres) wrote :

Actually I have to change that. According to termie's info on account crud (email, password, etc.) I think Horizon actually does need a service admin account. Which sucks because user's should be able to update their own account info – but that's another conversation.

from IRC:

termie> ohnoimdead: at this point no, a user can't update their own password
termie> all crud is admin api only
termie> ohnoimdead: you, obviously could use horizon's admin user to allow it
termie> ohnoimdead: and assume that you've validated the user's identity locally first