aboutcode-org / aboutcode-org/dejacode

BUG: User in legal group and with staff status is effectively a superuser

Abierto
#266 0 comentarios 0 reacciones 0 asignados Ver en GitHub
bug design needed enhancement
Lenguaje dominante
Python
Estrellas
50
Forks
27
Merge medio
4 h 51 min
PR fusionados (30 d)
11

Descripción

**Describe the bug**
Users that are assigned to the "Legal" group and have _Staff Status_ enable, currently posses the following permissions among others, as documented by the permission matrix:

- Change dataspace
- Add users
- Change users

This appears to have unintended or at least unexpected consequences from the perspective of DejaCode users. Users with the permissions as described above can perform the following actions:

- Increase their privilege by making themselves a superuser
- Remove permissions from higher privileged accounts such as superusers
- Deactivating higher privileged users such as superusers

As such assigning a user to the "Legal" group and giving them _Staff Status_ is effectively the equivalent of making them a superuser.

**To Reproduce**
1. Create a user
2. Assign them to the "Legal" group
3. Enable _Staff Status_
4. Log in as the user you have created
5. Check that you can escalate your own privileges and edit superusers

**Expected behavior**

- Users should not be able to give themselves higher permissions
- Users should not be able to edit user accounts that have higher permissions than themselves
- It is questionable that the "Legal" group needs to manage the dataspace and users at all, as this is an administrative task

**Screenshots**
n.a.

**Context (OS, Browser, Device, etc.):**
n.a.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.