##// END OF EJS Templates
security: make sure the admin of repo can only delete comments which are from the same repo....
security: make sure the admin of repo can only delete comments which are from the same repo. - fixes IDOR issue - protects against other people comment deletion by repo admins.

File last commit:

r1:854a839a default
r1818:1ced1b24 default
Show More
setting-usergroup-permissions.rst
25 lines | 1.1 KiB | text/x-rst | RstLexer
/ docs / admin / setting-usergroup-permissions.rst

Setting User Group Permissions

To set User Group |repo| permissions, use follow these steps:

  1. From the |RCE| interface, select :menuselection:`Admin --> User Group --> Add User Group`
  2. Enter a group name and description, and select :guilabel:`Save`
  3. Select :guilabel:`edit` beside the new User Group. On the following screen you will see a number of tabs. Exploring these you will find the following most used options:
  • :guilabel:`Owner`: This allows you to change the User Group owner. As super-admin you will still have access to this, but changing the owner lets you delegate the user group management to another manager.
  • :guilabel:`Members`: This allows you to added or remove users from the group.
  • :guilabel:`User Permissions`: On the permissions tab you can set the permissions for each member. If not individually set, the members will inherit the default user permissions.
  • :guilabel:`Inherit from default settings`: On the Global Permissions tab you can uncheck this option and explicitly configure the permissions for the group.