Skip to content

Evaluate who can access admin #26413

@sunnyclimber456

Description

@sunnyclimber456

Currently, anyone with a guardian.co.uk google login can access the admin app 12.

Given that the admin app exposes features and settings which can have unintended consequences, it might be worth

  1. Defining which Google groups should have access to admin
  2. Restricting certain routes to a subset of those groups

The motivation for this was raised by @SiAdcock

Footnotes

  1. https://github.com/guardian/frontend/blob/1567b3aa951cb707b04f106ba64e07fb3ddea628/common/app/conf/GoogleAuth.scala#L42

  2. https://github.com/guardian/frontend/pull/24805

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions