unicef / refer-laaha

Apache License 2.0
2 stars 1 forks source link

User Role able to Navigate beyond their designated location & domain #1359

Closed joanmneney closed 1 year ago

joanmneney commented 1 year ago

User role, e.g. Country Admin for Zimbabwe in the Zimbabwe Sub Domain, is able to add content for Bangladesh.

This issue affects the following sections:

App working perfectly for:

https://www.loom.com/share/fa29a349bcac4df8a7e6624ca8e5fc4b

mlncn commented 1 year ago

Followup from #1342

mlncn commented 1 year ago

Meanwhile /manage-location is somehow a custom listing not a Drupal View. But if we filter it to the current country based on domain, we shouldn't even have a "Click to Change Country" link or?

As we work to clean this up, one question is to what extent country admins should not be able to basically go to a subdomain not of their country at all when not logged in, and how much what we really want is the correct country pre-selected on every listing or form (but it's possible to navigate to a different domain / change the default), and how much we have to absolutely prevent Zimbabwe Country Admin from posting Bangladesh content and vice versa.

mlncn commented 1 year ago

People should not be able to post or edit content in a country they are not associated with.

mlncn commented 1 year ago

There should not be a "Click to change country" link, instead "Click to change location"