-
-
Notifications
You must be signed in to change notification settings - Fork 2.2k
Open
Labels
Description
Describe the Bug
I believe this is currently "as expected", however its an issue a user brought up to me last week.
I currently have all user assigned roles to not include delete capabilities, so that nothing is removed without an administrators consent.
However, uses with Edit permission can simply edit the permissions of the entity and uncheck Inherit defaults, allowing them to grant permission to delete the book/page/etc.
Steps to Reproduce
- Remove delete permissions from a role for all entities, but leave edit permissions
- Simply uncheck Inherit defaults, and check the delete permission. You can now delete the entity.
Expected Behaviour
Ideally, specifically for the delete function, this should be disabled when it is unchecked on a role level. Users should not be able to access the delete button by manually assigning permissions.
At the very least, this should be a separate toggle on a role level.
Screenshots or Additional Context
No response
Browser Details
No response
Exact BookStack Version
v25.02.3