Reconsider administer permission for canonical route

Created on 13 September 2023, over 1 year ago

I understand the custom route provider uses the administer permission for controlling access to the canonical route because it's an admin path, but I'm not sure that's necessary. Simply being in an admin path does not imply full administration rights to an entity. In this case, it means that the only users who have the ability to view licenses must have full rights to edit and delete them as well.

I'd advocate for maintaining a view only permission. Bear in mind that "view any" style permissions are themselves often reserved only for administrators or trusted roles. We also have a permission for "Access the licenses overview page." I can't imagine why a user with that permission and "View any licenses" shouldn't be able to access a canonical license route.

(If the issue is that elements on the view page may also result in edits, we'd just need to make sure those components are themselves properly access controlled.)

πŸ“Œ Task
Status

Active

Version

3.0

Component

Code

Created by

πŸ‡ΊπŸ‡ΈUnited States rszrama

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024