Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Permission settings: limited permissions with access-permissions enabled #4825

Closed
gagaha opened this issue Nov 2, 2016 · 1 comment
Closed

Comments

@gagaha
Copy link

gagaha commented Nov 2, 2016

Your Rocket.Chat version: 0.44

Let's say you have a role semi-admin that has permissions to do almost everything but don't has permissions to assign admin role in order to prevent it from deleting original admin accounts. If a user of this role has permission to access the permission settings he can simply give himself the permission to assign admin role and can also create new roles that have permission to assign admin role.
My workaround at the moment is, that this role has no access to the permissions but in future I would prefer users of this role to be able to create and manage roles.

Possible solution:
if a custom role has access-permissions checked but some other permissions unchecked then it should not be able to assign itself those permissions or create new roles with those specific permissions.

@ggazzo
Copy link
Member

ggazzo commented Feb 3, 2020

closed by #8942

@ggazzo ggazzo closed this as completed Feb 3, 2020
@tassoevan tassoevan added stat: triaged Issue reviewed and properly tagged and removed Triaged labels Oct 27, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants