aboutcode-org / aboutcode-org/dejacode

BUG: User in legal group and with staff status is effectively a superuser

未关闭
#266 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
bug design needed enhancement
主要语言
Python
星标
50
派生
27
平均合并
4 小时 51 分钟
30 天内合并 PR
11

描述

**Describe the bug**
Users that are assigned to the "Legal" group and have _Staff Status_ enable, currently posses the following permissions among others, as documented by the permission matrix:

- Change dataspace
- Add users
- Change users

This appears to have unintended or at least unexpected consequences from the perspective of DejaCode users. Users with the permissions as described above can perform the following actions:

- Increase their privilege by making themselves a superuser
- Remove permissions from higher privileged accounts such as superusers
- Deactivating higher privileged users such as superusers

As such assigning a user to the "Legal" group and giving them _Staff Status_ is effectively the equivalent of making them a superuser.

**To Reproduce**
1. Create a user
2. Assign them to the "Legal" group
3. Enable _Staff Status_
4. Log in as the user you have created
5. Check that you can escalate your own privileges and edit superusers

**Expected behavior**

- Users should not be able to give themselves higher permissions
- Users should not be able to edit user accounts that have higher permissions than themselves
- It is questionable that the "Legal" group needs to manage the dataspace and users at all, as this is an administrative task

**Screenshots**
n.a.

**Context (OS, Browser, Device, etc.):**
n.a.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。