cindy | Posts: 380

Delete sender account via sender UI

0 votes

Hi,

our client tried to delete account in the Owner account via Sender UI, after he clicked 'x' (delete) button, nothing happened in the GUI, but we found there is error in the log, any idea?

 

2020-09-28 19:37:37,408 INFO  [com.silanis.esl.web.exception.mappers.AbstractEslExceptionMapper] (default task-90) User: qCK8OJsWAeA9 | ForbiddenException : null : returning status: Forbidden : key=error.for
bidden.deleteAccountOwner

 

thanks,

Cindy


Duo_Liang | Posts: 3776

Reply to: Delete sender account via sender UI

0 votes

Hi Cindy,

 

Is this failed to be deleted sender:

- a former account owner merged into this account

- or, used to be the account owner in this account, and later be switched ownership

These two scenarios follow the error message that you were trying to delete a (former) account owner. Or if this is not the case, are you aware how do your client invited this sender? Manually choose the menu option “invite sender” from sender UI or through a custom sender tool?

 

Duo

 


cindy | Posts: 380

Reply to:

0 votes

we are in this scenario -"used to be the account owner in this account, and later be switched ownership"

Beginning: A is the owner, and B is the sender under A

After switch ownership: B is the owner, A is the sender under B, and B tried to delete A.

so do you mean this scenario doesn't valid? can't delete A after switch ownership? if so, if the Owner A leaves the company, how can we delete owner A properly?

thanks,

Cindy


Duo_Liang | Posts: 3776

Reply to: Delete sender account via sender UI

0 votes

Hi Cindy,

 

It's internally confirmed that due to a technicality in Hibernate, OneSpan Sign disables the deletion of a former account owner. However, I believe "if a sender A leaves the company, how can we delete owner A properly" is a more general question, and normally we suggest to lock the sender instead of deleting. in which case the sender lost his/her access to both UI and API.

 

Duo 


cindy | Posts: 380

Reply to:

0 votes

Hi Duo,

few questions: 

1) is this a bug in our current version? and will Onespan Sign consider to fix it in the future? 

2) what's the difference between lock the sender or suspend the sender? Does 'suspend' only be done by admin? 

3) by disabling this function, our security might have concern the new owner (or their delegates) could re-enable the old owner’s account, and suddenly someone who has left the company has the ability to send docs on CIBC’s behalf.  Admittedly it’s a small risk that this behavior would occur, but security tends to be pretty conservative about risks.

 

 


Duo_Liang | Posts: 3776

Reply to: Delete sender account via sender UI

0 votes

Hi Cindy,

 

I understand your concerns. Here're some of my thoughts for your questions:

1) is this a bug in our current version? and will Onespan Sign consider to fix it in the future? 

I believe "Can't delete former account owner" is an expected behavior, but of course we can still report this to R&D team for further confirmation.

 

2) what's the difference between lock the sender or suspend the sender? Does 'suspend' only be done by admin? 

Suspend can only be done through backoffice, but from API's perspective, both operations displayed as "LOCKED" status, and can be undone by "Manager" sender.

 

3) by disabling this function, our security might have concern the new owner (or their delegates) could re-enable the old owner’s account, and suddenly someone who has left the company has the ability to send docs on CIBC’s behalf. 

If your concern is the incorrect operation performed by admin user, will (1)change the sender type to "Regular" (2)lock or suspend the sender (3)merge the locked senders to a separate account where all email templates are disabled, helped to facilitate the use case?

 

Duo

 


Hello! Looks like you're enjoying the discussion, but haven't signed up for an account.

When you create an account, we remember exactly what you've read, so you always come right back where you left off