dropbox / dropbox/hackpad

Privacy and Admin Privileges Questions

Open
#42 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
3.6k
Forks
519
PR merge metrics
No merged PRs in 30d

Description

Hello,

I'm with a nonprofit called Worldreader and we have noticed that pads set to the "all workspace members can access" privacy setting are still viewable by anyone with access to the URL. While the "invitees only" setting removes this issue, it then requires everyone to be invited to each pad to view it, which is not ideal for a number of reasons (ex: large number of invitations, adding new users, etc.) Is it possible to have a sort of mid-level privacy setting that allows pads and their URL to be exclusively viewable to Worldreader users without being invited?

In addition, we have a large number of pads that have the "public" setting and it seems that only the creator/owner of the pad is able to change the setting. Thus, is there a way to bestow administrative privileges on a user so that they can correct this issue instead of having each individual user change the settings of the pads they own?

Thank you for your help in clarifying these issues.

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. First clarify the intended privacy levels and administrative scope, then trace how pad visibility and owner-only setting changes currently work. Done means defining an approved way for workspace users to access eligible pads and for administrators to update existing pad settings.

Written by the indexing model from the issue text.

Assessment

Domain
authorization, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.