aboutcode-org / aboutcode-org/dejacode

BUG: User in legal group and with staff status is effectively a superuser

Aberta
#266 0 comentários 0 reações 0 responsáveis Ver no GitHub
bug design needed enhancement
Linguagem predominante
Python
Estrelas
50
Forks
27
Merge médio
4h 51min
PRs com merge (30d)
11

Descrição

**Describe the bug**
Users that are assigned to the "Legal" group and have _Staff Status_ enable, currently posses the following permissions among others, as documented by the permission matrix:

- Change dataspace
- Add users
- Change users

This appears to have unintended or at least unexpected consequences from the perspective of DejaCode users. Users with the permissions as described above can perform the following actions:

- Increase their privilege by making themselves a superuser
- Remove permissions from higher privileged accounts such as superusers
- Deactivating higher privileged users such as superusers

As such assigning a user to the "Legal" group and giving them _Staff Status_ is effectively the equivalent of making them a superuser.

**To Reproduce**
1. Create a user
2. Assign them to the "Legal" group
3. Enable _Staff Status_
4. Log in as the user you have created
5. Check that you can escalate your own privileges and edit superusers

**Expected behavior**

- Users should not be able to give themselves higher permissions
- Users should not be able to edit user accounts that have higher permissions than themselves
- It is questionable that the "Legal" group needs to manage the dataspace and users at all, as this is an administrative task

**Screenshots**
n.a.

**Context (OS, Browser, Device, etc.):**
n.a.

Guia de contribuição

Abrir o guia de contribuição

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.