Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Non-authorised DDHPAT users can Watch targets #689

Open
crarugal opened this issue Oct 20, 2022 · 3 comments
Open

Non-authorised DDHPAT users can Watch targets #689

crarugal opened this issue Oct 20, 2022 · 3 comments

Comments

@crarugal
Copy link

crarugal commented Oct 20, 2022

This possibly relates to #621 (it's still unclear if issue 621 is caused by a bug, or ACT users)

Example target: https://www.webarchive.org.uk/act/targets/168983

It seems that "archivist" roles, who aren't authorised to Watch targets, can do so:
image

image

However, "expert_user" roles are still unable to Watch targets:
image
image

@anjackson
Copy link
Contributor

Back in #588 this appears to have been the desired behaviour!?

@crarugal
Copy link
Author

I'm not sure if this is the intended behaviour @nicolabingham. It looks like any Archivist role can make any target a Watched target, even if they don't have DDHAPT permission. I tested it with this test Archivist account:

image

Not a Watched target
image

Archivist role with DDHAPT disabled, still able to make the target Watched:
image

I think #588 questioned the editing of targets between Archivist roles who had DDHAPT enabled.
But from what I can see, any Archivist role can Watch a target, so it seems that disabling or enabling DDHAPT doesn't change anything if you have an Archivist role.

@nicolabingham
Copy link

A review of users in ACT has found nearly 30 users with the Archivist role, which is wrong as there should be only one person at each institution with this role, except the BL which needs more than one for admin purposes. This is a separate issue and I'll review individual users in ACT.
In terms of DDHAPT, access should not be automatic. An Archivist should be able to enable DDHAPT access for ACT users, but only on a case by case basis, so if users can create Watched Targets without having permission, this is a bug.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants