-
Notifications
You must be signed in to change notification settings - Fork 8
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
You have to know a user's password to add them to a group #45
Comments
I see your point from the perspective of us being the only ones managing the whole emoncms installation. But on the other hand it makes sense that you cannot add users to a group (and have access to their accounts) without some kind of consent. |
I understand your point. I wonder if there is a way we can set things up so both situations can be accomodated? I think the security model at the moment is the thing that holds this back - it seems to me that being able to create groups or log in as other users should have some kind of permission control that isn't about knowing other people's passwords or usernames. I'm imagining some kind of least privilege-style capabilities system like e.g. WordPress/Civi/AWS use, so that you can only do these things if you are explicitly granted the ability to do them. Then you'd have a capability like 'Can add members to groups (passwordless)' as well as perhaps 'Can add members to groups (with password)'. I guess that's what I was wondering about in #46 as well. |
This has been unhelpful in setting up groups for Nobel Grid - I wanted to set up groups for the different sites we have installations at and I can't add the right users to them.
The text was updated successfully, but these errors were encountered: