Project

General

Profile

Actions

Feature #270

open

Epic #49: Implement user, groups and permissions management

Understanding access

Feature #270: Understanding access

Added by Bricklou 9 days ago. Updated 8 days ago.

Status:
Planned
Priority:
Normal
Assigned To:
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
(Total: 0:00 h)

Description

A permission system nobody can explain becomes a system nobody trusts. With denials in play, "why can this person do that" and "why can't they" must both be answerable without reading the database.

An administrator can see everything a person can do and where each of those came from, ask why one specific action was allowed or refused for one person on one object, and see who has access to a given object and through what. The interface only offers people the actions they can actually perform, while the server still checks every request.


Rejection reason

Superseded by the rewritten epic #49


Subtasks 4 (4 open — 0 closed)

User Story #292: As an administrator, I want to see everything a person can do and where it came from, so that I can check their access at a glancePlannedBricklou

Actions
User Story #293: As an administrator, I want to ask why one person was allowed or refused one action, so that I can fix access instead of guessingPlannedBricklou

Actions
User Story #294: As the owner of a server, I want to see who has access to it and how, so that I can tell whether it is shared more widely than I thoughtPlannedBricklou

Actions
User Story #295: As a user, I want the interface to only offer me what I can actually do, so that I am not led into refusalsPlannedBricklou

Actions
Actions

Also available in: PDF Atom