Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Server Update Notifications for Non-Admins #518

Open
fdjohnston opened this issue Oct 13, 2021 · 0 comments
Open

Server Update Notifications for Non-Admins #518

fdjohnston opened this issue Oct 13, 2021 · 0 comments

Comments

@fdjohnston
Copy link

The Problem:
As a security best practice I recently made some changes to our Rocket.Chat instance so that none of our day-to-day accounts have the Administrator role. This role is only held by a single account with a strong password + 2FA that can be used to modify server settings, create new users, etc.
There is currently no way for non-admin users to receive notifications from Rocket.Chat when new server versions are available.

Under the update checker permission (General->Update) I see that it says:

“Checks automatically for new updates / important messages from the Rocket.Chat developers and receives notifications when available. The notification appears once per new version as a clickable banner and as a message from the Rocket.Cat bot, both visible only for administrators.”

The Solution:
It would be great if these notifications were controlled by a permission config that defaults to the Administrator role that could also be enabled for other roles. In this way one could lock down the administrator account and only use it when needed (Adding new users, changing settings, etc) but still receive notifications on a "daily driver" account when new server versions are available.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant