-
Notifications
You must be signed in to change notification settings - Fork 35
Improved: Added Me tab and enhanced permission handling for user list access with separate rule (#371) #373
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
… access with separate rule (hotwax#371)
Summary of ChangesHello @rakshit-upadhyay214, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request significantly refines user access control and navigation within the application. It introduces a dedicated 'Me' tab for individual user profile management and restricts access to sensitive user and permission management screens based on a new Highlights
🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console. Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Code Review
This pull request effectively introduces a 'Me' tab and enhances permission handling for the user list. Users lacking the USERS_LIST_VIEW permission are now correctly restricted from accessing the Users and Permissions screens, and are instead shown a 'Me' page with their own details. The changes also allow users with base-level permissions to reset their own passwords. The implementation across routing, components, and state management is consistent and well-executed. I have one minor suggestion to improve code quality by removing an unused variable.
src/authorization/Rules.ts
Outdated
| 'APP_USER_CREATE': 'SECURITY_CREATE OR SECURITY_ADMIN', | ||
| 'APP_UPDT_BLOCK_LOGIN': 'SECURITY_CREATE OR SECURITY_ADMIN', | ||
| 'APP_UPDT_PASSWORD': 'SECURITY_CREATE OR SECURITY_ADMIN', | ||
| 'APP_UPDT_PASSWORD': 'SECURITY_CREATE OR SECURITY_ADMIN OR USERS_APP_VIEW', |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think we should not add USERS_APP_VIEW permission, as adding it here will enable reset password feature for all the users, means that a random user can change password for admin or super users.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Users with only USERS_APP_VIEW can't do this as they are not allowed to access other users’ detail page. However, we can also introduce a separate permission specifically for password reset if needed.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, but if a user has USERS_LIST_VIEW permission, then he can access other users detail page and in that case the user can change other users password.
… button, allowing user to reset his own password (hotwax#371)
…ers instead of being dependent on props (hotwax#371)
Related Issues
#371
Description
Added a Me tab and enhanced permission handling for the user list. Users without the USERS_LIST_VIEW permission are now restricted from accessing the Users and Permissions screens. Also enabled all users with the base-level permission to reset their own password.
User with only USERS_APP_VIEW permission:
