apostrophecms / apostrophecms/apostrophe

Must document A2's requirement that "guest" permission be granted to a user or group before they can view "login required" content

Open
#2,751 1 comment 0 reactions 0 assignees View on GitHub
bug
Dominant language
JavaScript
Stars
4.6k
Forks
650
Avg merge
19h 21m
Merged PRs (30d)
23

Description

File in apostrophe-permissions/lib/strategiesApi.js Line 46
![image](https://user-images.githubusercontent.com/26570009/108823955-6a732100-75c1-11eb-9053-501f02ef90a2.png)

It should not be necessary to have the guest permission to see objects with loginRequired.

In the boilerplate the guest user doesn´t have any permissions and in the documentation there are no information about this behaviour.

It should be enough to be a logged in user

Contributor guide

Open the contributing guide

Research direction

Start at apostrophe-permissions/lib/strategiesApi.js line 46 and review the linked screenshot and issue description to confirm how loginRequired content is gated. Check the existing documentation and boilerplate permission setup; done means clearly documenting the guest-permission requirement, or recording the confirmed logged-in-user behavior if maintainers decide it should change.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
authorization, documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.