Skip to content

Conversation

@thomas-Ngr
Copy link
Contributor

NEW Move right "Modify thirdparty information payment" out of advanced rights

@eldy eldy added the Discussion Some questions or discussions are opened and wait answers of author or other people to be processed label Apr 9, 2025
$this->rights[$r][1] = 'Modify thirdparty information payment';
$this->rights[$r][3] = 0;
$this->rights[$r][4] = 'thirdparty_paymentinformation_advance'; // Visible if option MAIN_USE_ADVANCED_PERMS is on
$this->rights[$r][4] = 'thirdparty_paymentinformation';
Copy link
Member

@eldy eldy Apr 9, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The idea behind the permission is that we must have in the default mode only 3 permission
read, update/write and delete + some if it is really not possible to use the application without.
As soon as we want to have a more accurate permission level, it is advanced permissions.

Can you describe your use case and why it is absolutely necessary that all company need to manage this permission differently than modifying the thirdparty ?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This permission should be available without enabling advanced permissions, because editing bank account data (like IBANs) involves a major fraud risk.
Many companies must limit access to bank details to a specific group (e.g., accounting or finance), while still allowing others to edit general thirdparty data. Without this separation, every user who can edit a thirdparty could potentially change critical bank info — which is a serious security concern.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can confirm that this is a recurrent request from customers who want this right so as not to leave the door open to any modification and without activating the advanced rights.

@thomas-Ngr thomas-Ngr force-pushed the develop_move_right_thirdparty_information branch from 8143ea8 to bc8985e Compare April 16, 2025 10:37
@eldy
Copy link
Member

eldy commented Apr 16, 2025

I still not have permission to merge the PR. Can you push it from a non locked repository ?

@thomas-Ngr
Copy link
Contributor Author

thomas-Ngr commented Apr 17, 2025

@eldy I restarted the PR here : #33885

@thomas-Ngr thomas-Ngr closed this Apr 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Discussion Some questions or discussions are opened and wait answers of author or other people to be processed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants