Skip to content
This repository has been archived by the owner on Jul 16, 2022. It is now read-only.

Autorole security #198

Open
oskikiboy opened this issue Sep 7, 2017 · 2 comments
Open

Autorole security #198

oskikiboy opened this issue Sep 7, 2017 · 2 comments
Labels
priority: Substantial Issues that require substantial priority to be handled s: In Progress Issues which are WIP and should not be finished/merged. The issue is in progress target: Web Issues that target GAB's Web Server type: Enhancement Issues that enhance an existing feature or module type: Suggestion Issues that suggest source changes

Comments

@oskikiboy
Copy link

if you have admin access to the dashboard you shouldn't be allowed to set an auto add role thats above you

@vladfrangu vladfrangu added target: Web Issues that target GAB's Web Server type: Enhancement Issues that enhance an existing feature or module type: Suggestion Issues that suggest source changes labels Sep 7, 2017
@vladfrangu
Copy link
Member

To explain:

Lets say you have a role beneath the top one. If you get access to the admin panel (through some way), you shouldn't be allowed to add the role thats above you to the auto join. Owner should be able to add any roles tho

@Gilbert142 Gilbert142 added priority: Substantial Issues that require substantial priority to be handled s: In Progress Issues which are WIP and should not be finished/merged. The issue is in progress labels Sep 7, 2017
@Gilbert142
Copy link
Member

Agreed. Will add this functionality in 4.1.

Check the PR for progress: #184

@Gilbert142 Gilbert142 reopened this Sep 7, 2017
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
priority: Substantial Issues that require substantial priority to be handled s: In Progress Issues which are WIP and should not be finished/merged. The issue is in progress target: Web Issues that target GAB's Web Server type: Enhancement Issues that enhance an existing feature or module type: Suggestion Issues that suggest source changes
Projects
None yet
Development

No branches or pull requests

3 participants