|
Description
|
At present, group objects behave in different ways:
Group-set objects = no extra group permissions
Group-shared objects = anyone in a group can manipulate
Group-deeded (-owned) objects = only members in roles with "manipulate" permission can manipulate
The group-shared role is confusing, as per the constantly resurfacing SVC-121 issue.
The proposal is to treat group-shared objects the same as group-deeded objects, so that extra permission is only granted to members with "manipulate" permissions.
Would this be more clear? Can any point to existing group usage this would break?
|
At present, group objects behave in different ways:
Group-set objects = no extra group permissions
Group-shared objects = anyone in a group can manipulate or return
Group-deeded (-owned) objects = only members in roles with various permission can manipulate or return
The group-shared role is confusing, as per the constantly resurfacing SVC-121 issue.
The proposal is to treat group-shared objects the same as group-deeded objects, so that extra permissions are only granted to members with manipulate or return permissions.
Would this be more clear? Can any point to existing group usage this would break?
|