edisona / amcat

Automatically exported from code.google.com/p/amcat
1 stars 0 forks source link

restrict splitting rights to admin? #627

Open GoogleCodeExporter opened 9 years ago

GoogleCodeExporter commented 9 years ago
Users can split articles in any project regardless of their status and the 
project's guest role. Splitting means permanently changing project data, so 
this probably should be restricted to admin status users only (that means, 
inaccessible to read/write status lower). 

Also, it seems that it is possible now for users to change their own status to 
admin or to add themselves to a project, which might also be something that is 
better to restrict to project owners.

Original issue reported on code.google.com by carinaja...@nieuwsmonitor.net on 30 Oct 2013 at 3:39

GoogleCodeExporter commented 9 years ago
ho, dat laatste klopt niet, kwam door mijn superadmin-status.

In elk geval, splitten valt nu onder read/write, maar codeurs zijn read/write 
en splitten kan de data van een project 'permanent' veranderen, dus is het niet 
beter om splitten een admin-right te maken?

Original comment by carinaja...@nieuwsmonitor.net on 30 Oct 2013 at 4:04