← Back to team overview

mahara-contributors team mailing list archive

[Bug 631189] Re: Non-group admin can manage group views and group files

 

I don't think there's an easy way to restrict editing of ordinary group
views.

But it would be quite easy to stop the group homepage view from being
edited by non-admins, and I think we should do that before the release.

Group files have view/edit permissions set individually for each file
and each role in the group, which is intentional.  If a group admin
uploads a file to a group and doesn't want ordinary members to be able
to edit it, s/he must edit the file in the group files area and set the
permission explicitly.

** Changed in: mahara
       Status: New => Confirmed

** Changed in: mahara
   Importance: Undecided => Medium

** Changed in: mahara
    Milestone: None => 1.3.0

-- 
Non-group admin can manage group views and group files
https://bugs.launchpad.net/bugs/631189
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.

Status in Mahara ePortfolio: Confirmed

Bug description:
Maybe its intended, but a group member who is not an admin of that group can add, delete and edit group views and files. 

1.3.0rc1
MySQL
Linux





References