Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Directory menu allows to see list of users even if the creation of channels is disabled #10204

Closed
AntMarras opened this issue Mar 23, 2018 · 5 comments

Comments

@AntMarras
Copy link

AntMarras commented Mar 23, 2018

Description:

I revoked the permission to create public and private channels for certain user groups. The issue with this is, that from the Main Menu -> Directory is it still possible to try to create a channel (without success).
The problem is that such user can see the list of all users of the chat!

Server Setup Information:

version of Rocket.Chat Server: 0.62.2
Operating System: Ubuntu Server 16.04.4 LTS
Deployment Method(snap/docker/tar/etc): heroku
Number of Running Instances: 2
DB Replicaset Oplog: YES

Steps to Reproduce:

  1. Revoke permission for users to create new public & private channels
  2. Open Directory
  3. Try to create a new channel

Expected behavior:

The "plus" button should not appear in the Directory menu

Actual behavior:

The button is there

Relevant logs:

@TwizzyDizzy
Copy link

@rocket-cat close

Hi @AntMarras

we believe that the issue you reported has already been reported by somebody else. Please have a look at #10200 for further information. If you believe we closed your issue in error and your issue is, in fact, not the same as the one mentioned before, feel free to get back to us here and tell us why.

Cheers
Thomas

@rocket-cat rocket-cat bot closed this as completed Mar 23, 2018
@AntMarras
Copy link
Author

@TwizzyDizzy

I think is related but not the same:

if I disable the creation of channels for some user group, the button to create the channel is not present in the main menu but it is still present in the Directory menu allowing a user to try to create the channel (but failing) and (worse for me) to see the entire list of users. I hope I explained it better.

@AntMarras
Copy link
Author

AntMarras commented Mar 23, 2018

@TwizzyDizzy

I think that in the issue you linked the guy still has the create channel button in the main menu for the private channels but he want to disable the public channels. In my case that button is still present in the Directory even if I disabled the creation of Public AND Private channels.

Cheers

@TwizzyDizzy
Copy link

Mhhh... but still I think you're mixing two things here. Seeing users in the list has got nothing to do with the permission to create whatever channel, or am I getting something very wrong here? If somebody will tackle the other issue, I think she or he can then have a look at this whole topic.

I've added this passage to the other issue:

if I disable the creation of channels for some user group, the button to create the channel is not present in the main menu but it is still present in the Directory menu allowing a user to try to create the channel (but failing) and (worse for me) to see the entire list of users. I hope I explained it better.

Cheers
Thomas

@AntMarras
Copy link
Author

👍 for me. Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants