Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Disable access to profile list, set up Pundit policy to enforce who can edit what profile. #181

Open
rsmithlal opened this issue Mar 28, 2019 · 1 comment
Assignees
Labels

Comments

@rsmithlal
Copy link
Contributor

rsmithlal commented Mar 28, 2019

After updating your profile (or clicking that "back" button for your profile form, actually), you are redirected to https://alpha.joatu.org/en/profiles where you can see and edit all the profiles in the system.

We need to remove this application route (no point to list profiles to regular users), and enforce authorization checks for who can view the list of profiles.

@rsmithlal rsmithlal added the bug label Mar 28, 2019
@rsmithlal rsmithlal self-assigned this Mar 28, 2019
@joatu
Copy link
Contributor

joatu commented Mar 28, 2019

I think you can edit them because you're admin. Otherwise, it's just a list, no? And sure, it's fine to disable for now, but later on, it would make sense to be able to see the members of the group (if chosen to be enabled) via better together.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants