aboutcode-org / aboutcode-org/dejacode

BUG: User in legal group and with staff status is effectively a superuser

オープン
#266 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug design needed enhancement
主要言語
Python
スター
50
フォーク
27
平均マージ
4時間 51分
マージ済み PR(30日)
11

説明

**Describe the bug**
Users that are assigned to the "Legal" group and have _Staff Status_ enable, currently posses the following permissions among others, as documented by the permission matrix:

- Change dataspace
- Add users
- Change users

This appears to have unintended or at least unexpected consequences from the perspective of DejaCode users. Users with the permissions as described above can perform the following actions:

- Increase their privilege by making themselves a superuser
- Remove permissions from higher privileged accounts such as superusers
- Deactivating higher privileged users such as superusers

As such assigning a user to the "Legal" group and giving them _Staff Status_ is effectively the equivalent of making them a superuser.

**To Reproduce**
1. Create a user
2. Assign them to the "Legal" group
3. Enable _Staff Status_
4. Log in as the user you have created
5. Check that you can escalate your own privileges and edit superusers

**Expected behavior**

- Users should not be able to give themselves higher permissions
- Users should not be able to edit user accounts that have higher permissions than themselves
- It is questionable that the "Legal" group needs to manage the dataspace and users at all, as this is an administrative task

**Screenshots**
n.a.

**Context (OS, Browser, Device, etc.):**
n.a.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。