nuxsmin / sysPass

Systems Password Manager
https://syspass.org
GNU General Public License v3.0
975 stars 208 forks source link

Groups and Passwords #1333

Open Felsser opened 5 years ago

Felsser commented 5 years ago

sysPass Version sysPass 3.1-RC2

Describe the question After some failed tries with teampass I found syspass which looks neat, but here I stumbled upon some Rights-Management issue:

I've created 2 profiles Admin and User group. also I created 2 groups Admins and Users

User Group enabled: Add View View password Permissions Global search

now if one user creates a account, he is not able to hide it from others in his own group.

Basically what I need:

I tried to manage this trough preset values, but this doesn't affect primary group. If I could set it there to force primary group "admins" this would be good.

What did I miss?

Screenshots If applicable, add screenshots to help explain your problem.

Platform (please complete the following information):

Additional context Add any other context about the problem here.

nuxsmin commented 5 years ago

Hello, since the beginning, sysPass was designed to allow owners and their main group to have access to the accounts they create. This is so because sysPass was developed with business in mind, so creating owner-only accounts is against a collaborative password manager, though later this was possible by using private mode, but it needs to be allowed by a profile administrator, so the "business" would be able to decide who can create private accounts...

This feature might be useful, but it would need to be implemented through an administrator option, because it will affect the whole app behavior.

Regards

nuxsmin commented 5 years ago

Thanks for the feedback!

Felsser commented 5 years ago

Hello nuxsmin,

keeping business in mind, wouldn't be an option to set this as preset values. "If user creates account, set primary group "XYZ?" (in my case "Admin" group) so "owner", "group XYZ" can share this account with whom they decide to share it?

And it won't affect the whole app behavior for everyone.