-
Notifications
You must be signed in to change notification settings - Fork 199
Admins cannot view /package/:package/maintain #124
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Should be easy to fix. There's an auth check that uses a list of groups. |
Admins (who administer users/infrastructure) shouldn't need to do this, right? This should be in the realm of trustees (who administrate packages). If there are admins who are also de facto trustees, they should be added to the trustees group. (All of the links on the maintain page should probably be changed likewise.) |
I've looked into this a bit further. All html pages linked from the 'maintain' page have no security checks, but the actual actions all call So the question here really is what we want. Adding a maintainer (usually for a package takeover) is something we now do regularly as admins, so it would be convenient if the index page is viewable. If we decide that this is not a task for admins but only for trustees, then the permissions for the editing of maintainers should be tightened. |
I would suggest we eliminate |
So should we make this change? |
i think we should, yes? |
Users in the admins group cannot view
/package/:package/maintain
, but they can access all the links on that page. I think they should also be able to view that page.The text was updated successfully, but these errors were encountered: