Allow only k-space:janitor to modify anything with keys. #14

Closed
opened 2024-08-02 06:51:28 +00:00 by rasmus · 4 comments
Owner

Currently, anyone can add/edit/change usership of keys. Make items with type:key read-only to people without the group.

Currently, anyone can add/edit/change usership of keys. Make items with type:key read-only to people without the group.
madis self-assigned this 2024-08-03 16:52:34 +00:00
Author
Owner

Edit: It'd be better if this gets a 2nd group (please document OIDC groups in README or similar), k-space:inventory:keys (I think it would be best if k-space:janitor was renamed to k-space:inventory:admin (or k-space:inventory:audit and k-space:inventory:edit). Pardon for giving conflicting opinions with my earlier ones.

Edit: It'd be better if this gets a 2nd group (please document OIDC groups in README or similar), k-space:inventory:keys (I think it would be best if k-space:janitor was renamed to k-space:inventory:admin (or k-space:inventory:audit and k-space:inventory:edit). Pardon for giving conflicting opinions with my earlier ones.
Owner

Added by aa76374f1f, 3dfda0ac7f.

Added by aa76374f1f61a2f75c824d3891dfa50411d71649, 3dfda0ac7f07514572a89463e12c3c0be8ac947d.
madis closed this issue 2024-08-29 14:16:20 +00:00
Owner

Documenting oidc groups tracked in #16

Documenting oidc groups tracked in #16
Owner

@rasmus reverted in production until user crd-s are synced.

@rasmus reverted in production until user crd-s are synced.
Sign in to join this conversation.
No Label
greenlit
No Milestone
No project
No Assignees
2 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: k-space/inventory-app#14
No description provided.