code-corps / code-corps/code-corps-api
Step through policies for projects, organizations, memberships
- Vorherrschende Sprache
- Elixir
- Sterne
- 234
- Forks
- 82
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
# Problem
This part of our system is probably the complex and I'm not sure it was properly finalized.
Now that we're switching from `OrganizationMembership` to a `ProjectUser` + `:owner` system, we need to step through and figure out exactly how it should work.
# For projects
## Who can edit project information - just owner, members?
Once we merge #735, organization owners will be able to create projects. Project owners and project admin members will be able to update information. Is this correct?
## Who can manage project associations - skills, categories
Once we merge #735, this will be owners and admins. Is this correct?
## Who can manage project memberships, how do they compare to one another based on role
This definitely needs some work. Our current `ProjectUserPolicy` checks against the acting user's `ProjectUser` record, but does not check if the acting user is the outright project owner.
## What roles do we have?
Should we still keep the "owner" role, or should we exclusively check the `owner_id` on the project? Are the two ever different? If we are keeping the role, we need to make sure everything is properly associated upon project creation and a role is created.
# For organizations
Do we expect a case where some user is a project owner, but they are not the associated organization's owner?
Beitragsleitfaden
Bewertung
Dieses Issue wurde noch nicht bewertet.