summaryrefslogtreecommitdiff
path: root/issues/gn-auth/problems-with-roles.gmi
diff options
context:
space:
mode:
Diffstat (limited to 'issues/gn-auth/problems-with-roles.gmi')
-rw-r--r--issues/gn-auth/problems-with-roles.gmi7
1 files changed, 4 insertions, 3 deletions
diff --git a/issues/gn-auth/problems-with-roles.gmi b/issues/gn-auth/problems-with-roles.gmi
index 46f3c52..2778b61 100644
--- a/issues/gn-auth/problems-with-roles.gmi
+++ b/issues/gn-auth/problems-with-roles.gmi
@@ -3,9 +3,9 @@
## Tags
* type: bug
-* status: open
* priority: critical
* assigned: fredm, zachs
+* status: closed, completed, fixed
* keywords: gn-auth, authorisation, authorization, roles, privileges
## Description
@@ -29,8 +29,8 @@ The implementation should instead, tie the roles to the specific resource, rathe
* [x] migration: Add `resource:role:[create|delete|edit]-role` privileges to `resource-owner` role
* [x] migration: Create new `resource_roles` db table linking each resource to roles that can act on it, and the user that created the role
* [x] migration: Drop table `group_roles` deleting all data in the table: data here could already have privilege escalation in place
-* [ ] Create a new "Roles" section on the "Resource-View" page, or a separate "Resource-Roles" page to handle the management of that resource's roles
-* [ ] Ensure user can only assign roles they have created - maybe?
+* [x] Create a new "Roles" section on the "Resource-View" page, or a separate "Resource-Roles" page to handle the management of that resource's roles
+* [x] Ensure user can only assign roles they have created - maybe?
### Fixes
@@ -39,3 +39,4 @@ The implementation should instead, tie the roles to the specific resource, rathe
=> https://git.genenetwork.org/gn-auth/commit/?h=handle-role-privilege-escalation&id=5d34332f356164ce539044f538ed74b983fcc706
=> https://git.genenetwork.org/gn-auth/commit/?h=handle-role-privilege-escalation&id=f691603a8e7a1700783b2be6f855f30d30f645f1
=> https://git.genenetwork.org/gn-auth/commit/?h=handle-role-privilege-escalation&id=2363842cc81132a2592d5cda98e6ebf1305e8482
+=> https://github.com/genenetwork/genenetwork2/commit/a7a8754a57594e5705fea8e5bbea391a09e8f64c