sftpgo-mirror/templates
Nicola Murino d0f348a46a
WebAdmin and REST API: remove too granular permissions
Our permissions system for admin users is too granular and some
permissions overlap. For example, you can define an administrator
with the "manage_system" permission and not with the "manage_admins"
or "manage_user" permission, but the "manage_system" permission
allows you to restore a backup and then create users and
administrators. The following permissions will be removed:
"manage_admins", "manage_apikeys", "manage_system", "retention_checks",
"manage_event_rules", "manage_roles", "manage_ip_lists". Now you
need to add the "*" permission to replace the removed granular
permissions because the removed permissions allow actions that
should only be allowed to super administrators.
There is no point in having separate, overlapping permissions.

Signed-off-by: Nicola Murino <nicola.murino@gmail.com>
2024-11-10 10:51:27 +01:00
..
common WebClient: improve readability of upload progress 2024-10-03 20:31:46 +02:00
email WIP: new WebClient UI 2023-11-05 17:26:29 +01:00
webadmin WebAdmin and REST API: remove too granular permissions 2024-11-10 10:51:27 +01:00
webclient WebClient: update edit and preview file extensions 2024-10-04 19:22:06 +02:00