ArctosDB / arctos

Arctos is a museum collections management system
https://arctos.database.museum
60 stars 13 forks source link

audit cf_form_permissions #6144

Closed ebraker closed 1 year ago

ebraker commented 1 year ago

Loan: Create is not visible on the tool directory (or the table view). Where did it go? I can confirm it was available yesterday.

image

dustymc commented 1 year ago

https://arctos.database.museum/Loan.cfm?action=newLoan

I didn't do it! This has become somewhat common, what's going on? Do we need a log or something?? Maybe we can just attribute this to growing pains??

Or I suppose it's not entirely impossible that I have some dumb script or something, but I don't think so and can't find anything like that.

Here are people with the power:

  username      

acdoll campmlc ccicero dlm ebraker ewommack jegelewicz katherinelanderson lam ljmullen2 mkoo

Why does Katie have global_admin? Why does ljmullen2, and probably whomever gave ljmullen2 global_admin, have global admin?

I don't see this being accessed (other than by me right now) in the last few days via the webserver logs (but they're clunky, I could have missed it) - @ebraker how are you confirming? Could this have just been oopsied in whatever meeting that was when we updates a bunch of these?

HELP!

ebraker commented 1 year ago

Yikes. Wasn't me either (I only very occasionally add code table values a few times a year so I probably don't need global_admin).

I created two loans yesterday, invoices and all, so loans were accessible up until at least 1:46 pm when I saved the files.

At least that link will help get another one out today, but agreed, this is a major issue and we may need logs.

@Jegelewicz @mkoo @campmlc

campmlc commented 1 year ago

I haven't touched anything in code tables for at least this year, other than maybe add a collection to an existing value - or done anything else that would require global admin to my knowledge. I have been creating and editing loans, that's it. The create tool was there Monday.

campmlc commented 1 year ago

https://arctos.database.museum/Loan.cfm?action=newLoan

I didn't do it! This has become somewhat common, what's going on? Do we need a log or something?? Maybe we can just attribute this to growing pains??

Or I suppose it's not entirely impossible that I have some dumb script or something, but I don't think so and can't find anything like that.

Here are people with the power:

  username      

acdoll campmlc ccicero dlm ebraker ewommack jegelewicz katherinelanderson lam ljmullen2 mkoo

Why does Katie have global_admin? Why does ljmullen2, and probably whomever gave ljmullen2 global_admin, have global admin?

I don't see this being accessed (other than by me right now) in the last few days via the webserver logs (but they're clunky, I could have missed it) - @ebraker how are you confirming? Could this have just been oopsied in whatever meeting that was when we updates a bunch of these?

HELP!

I would also suggest that no one whose not an officer or at the very least a regular attendee of working group and issues meetings not be given global admin. Who are these people?

Jegelewicz commented 1 year ago

I haven't changed anything since the day we met up and made all the sweeping changes.

I agree we should remove global admin from Katie and ljmullen2

Jegelewicz commented 1 year ago

I revoked Global Admin for Katie - I am guessing this was something she had when it was necessary for something that we have since demoted to some new role. I did not revoke ljmullen2 because I don't feel comfortable with that one (I Know Katie).

ewommack commented 1 year ago

Didn't do it.

I created two loans yesterday, invoices and all, so loans were accessible up until at least 1:46 pm when I saved the files.

Sounds like Emily was in there later than I was on Tuesday, I don't remember if it was there when I was working on projects yesterday...

campmlc commented 1 year ago

Logan Mullen UAM Entomology MS graduate student 2013- @DerekSikes should this person have global admin?

ccicero commented 1 year ago

I see Loan: Create

image

Jegelewicz commented 1 year ago

Me too

image

ebraker commented 1 year ago

@ccicero @Jegelewicz - it wasn't there for anyone this morning but @dustymc added it back

dustymc commented 1 year ago

Blargh, see also https://github.com/ArctosDB/arctos/issues/6089#issuecomment-1507662929, I'm hijacking this (mostly in case its my bug...).

ewommack commented 1 year ago

Did we loose how to create an Accession when we lost how to create a Loan?

jldunnum commented 1 year ago

Yup, we are searching in vain as well. Help!

campmlc commented 1 year ago

Temp work around is to find an existing accession, go to edit page, follow link to create new at top.

campmlc commented 1 year ago

https://arctos.database.museum/accn.cfm?action=createForm

Jegelewicz commented 1 year ago

See also https://github.com/ArctosDB/arctos/issues/6155