Allow only k-space:janitor to modify anything with keys. #14
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Currently, anyone can add/edit/change usership of keys. Make items with type:key read-only to people without the group.
Edit: It'd be better if this gets a 2nd group (please document OIDC groups in README or similar), k-space:inventory:keys (I think it would be best if k-space:janitor was renamed to k-space:inventory:admin (or k-space:inventory:audit and k-space:inventory:edit). Pardon for giving conflicting opinions with my earlier ones.
Added by
aa76374f1f
,3dfda0ac7f
.Documenting oidc groups tracked in #16
@rasmus reverted in production until user crd-s are synced.