Remove email-editing footgun (#503)

* Remove email-editing footgun

Email address is used as the primary key so we should be very careful
about changing it. This will have even more importance when this is the
location to which we will be sending registry lock confirmation emails.

Note: we allow addition or removal of contacts through the UI (and don't
want to disable that) and because all edits are performed by saving the
entire list of contacts, we can't explicitly prevent all possible edits
of email address in the backend. So this doesn't technically prevent
anything security-wise, but it makes it much more difficult to
accidentally edit an email when you shouldn't.

* Enforce non-deletion of registry-lock-enabled contacts

* Fix tests

* Specify contact
This commit is contained in:
gbrodman
2020-04-29 11:44:51 -04:00
committed by GitHub
parent aa0dcea537
commit c361c9e601
10 changed files with 132 additions and 52 deletions
@@ -145,6 +145,7 @@
{param label: 'Email' /}
{param namePrefix: $namePrefix /}
{param name: 'emailAddress' /}
{param disabled: not $readonly and $item['emailAddress'] != null /}
{/call}
{call registry.soy.forms.inputFieldRow data="all"}
{param label: 'Phone' /}