Project

General

Profile

Actions

Feature #269

open

Epic #49: Implement user, groups and permissions management

Access decision and enforcement

Feature #269: Access decision and enforcement

Added by Bricklou 9 days ago. Updated 8 days ago.

Status:
Planned
Priority:
Normal
Assigned To:
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
(Total: 0:00 h)

Description

Everything granted is worthless unless it is actually applied, consistently, to every way of reaching the platform, and unless the rules produce one predictable answer when several grants apply at once.

Every protected action is checked before it runs and refused clearly when it is not permitted, whether it was reached through the interface, the API, or the command line. When several grants apply, the one closest to the object decides; within one place, an entry naming the person beats one naming a group they belong to, and a denial beats an allowance. Anything not decided is refused. Administrators are never refused. A change to a role, a grant, or group membership takes effect without anybody signing in again.


Rejection reason

Superseded by the rewritten epic #49


Subtasks 3 (3 open — 0 closed)

User Story #289: As an operator, I want every protected action checked before it runs, so that access rules cannot be bypassed by choosing another way inPlannedBricklou

Actions
User Story #290: As an administrator, I want one predictable answer when several grants apply at once, so that access never depends on the order things were set up inPlannedBricklou

Actions
User Story #291: As an administrator, I want a change to access to take effect straight away, so that revoking someone actually stops themPlannedBricklou

Actions
Actions

Also available in: PDF Atom