Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

When both Allow and Deny cropping leases are applied, Deny should win… #3860

Open
paperboyo opened this issue Sep 15, 2022 · 2 comments
Open

Comments

@paperboyo
Copy link
Contributor

Short description

…instead Allow wins, which is not safe.

Steps to reproduce

Ask someone to apply two active cropping leases: Allow and Deny. Try cropping image yourslef while not having edit_metadata permission. Cropping should be disabled.

Actual results

Cropping is allowed.

Expected results

Cropping should be denied.

OS and browser details

All.

@honorcb
Copy link
Collaborator

honorcb commented Oct 18, 2022

would you ever want to filter which group of users the allow or deny applies to?

for example do you ever want to allow Observer user to crop, but not the Guardian user? the division in BBC is between News teams and the Program production teams , News users are licenced to Crop agency images, and Program user not unless they pay.

@paperboyo
Copy link
Contributor Author

Yes, we were thinking about this as this sound helpful. But that’s about it – just thinking. I guess we could think about it as part of multi-tenancy discussions…

@paperboyo paperboyo changed the title When both Allow and Deny leases are applied, Deny should win… When both Allow and Deny cropping leases are applied, Deny should win… May 26, 2023
@paperboyo paperboyo mentioned this issue May 15, 2024
4 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants