Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Noordcie / zuidcie shouldn't have view-user permissions #508

Open
JobDoesburg opened this issue Sep 25, 2023 · 1 comment
Open

Noordcie / zuidcie shouldn't have view-user permissions #508

JobDoesburg opened this issue Sep 25, 2023 · 1 comment
Labels
bug Something isn't working.

Comments

@JobDoesburg
Copy link
Collaborator

We have 1290 TOSTI users with their credentials. That's quite a lot. I think it is good practice and data minimization to not give all staff users viewing permissions on these users.

Currently, noordcie and zuidcie members only have these permissions for manually creating orders and managing the blacklists.

In my opinion, they don't have to manually create orders linked to users (they can be anonymous or have a string field for name of the person that created them)

For the blacklists, we can implement a method to blacklist the person from a specific order.

@JobDoesburg
Copy link
Collaborator Author

Also, we should maybe write these fundamental design principles down somewhere in some README.md / CONTRIBUTING.md file.

@KiOui KiOui added the bug Something isn't working. label Oct 7, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working.
Projects
None yet
Development

No branches or pull requests

2 participants