[ 
http://jira.magnolia.info/browse/MAGNOLIA-574?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17489#action_17489
 ] 

Jan Haderka commented on MAGNOLIA-574:
--------------------------------------

I think that when the other related issues are resolved user won't be able to 
assign themselves groups/roles they do not have access to. The nwe can discuss 
whether it is appropriate to also disable this option in the dialog or not. But 
first of all we have to make sure users are not able to widen their own 
privileges themselves.
As for my personal opinion, I think it is ok to show user groups and roles they 
are assigned to. As well as to show them extra groups/roles that they have 
already enough privileges to assign to themselves. This way when admin is 
setting rights for the users they can easily check whether ACLs they are using 
have intended effect or not, rather then waiting for some smart user to 
discover how to assign something extra so themselves even if such options are 
not visible by default.

> User preferences
> ----------------
>
>                 Key: MAGNOLIA-574
>                 URL: http://jira.magnolia.info/browse/MAGNOLIA-574
>             Project: Magnolia
>          Issue Type: New Feature
>          Components: admininterface
>            Reporter: Boris Kraft
>            Assignee: Jan Haderka
>             Fix For: 3.6.2
>
>
> Mechanisms to have user preferences so that each user can change his own 
> preferences like password (obviously), email, name, language but also other 
> stuff (extensible) - one example is the change notification scheme. see 
> [MAGNOLIA-573]

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: 
http://jira.magnolia.info/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

----------------------------------------------------------------
for list details see
http://documentation.magnolia.info/
----------------------------------------------------------------

Reply via email to