code-corps / code-corps/code-corps-api

Step through policies for projects, organizations, memberships

未关闭
#725 0 条评论 0 个 reaction 已指派 2 人 已被 @joshsmith 认领 在 GitHub 查看
主要语言
Elixir
星标
234
派生
82
PR 合并指标
30 天内没有已合并 PR

描述

# Problem

This part of our system is probably the complex and I'm not sure it was properly finalized.
Now that we're switching from `OrganizationMembership` to a `ProjectUser` + `:owner` system, we need to step through and figure out exactly how it should work.

# For projects

## Who can edit project information - just owner, members?

Once we merge #735, organization owners will be able to create projects. Project owners and project admin members will be able to update information. Is this correct?

## Who can manage project associations - skills, categories

Once we merge #735, this will be owners and admins. Is this correct?

## Who can manage project memberships, how do they compare to one another based on role

This definitely needs some work. Our current `ProjectUserPolicy` checks against the acting user's `ProjectUser` record, but does not check if the acting user is the outright project owner.

## What roles do we have?

Should we still keep the "owner" role, or should we exclusively check the `owner_id` on the project? Are the two ever different? If we are keeping the role, we need to make sure everything is properly associated upon project creation and a role is created.

# For organizations

Do we expect a case where some user is a project owner, but they are not the associated organization's owner?

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。