Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Discrepancy re. admin permissions #446

Open
ctueck opened this issue Oct 13, 2022 · 0 comments
Open

Discrepancy re. admin permissions #446

ctueck opened this issue Oct 13, 2022 · 0 comments

Comments

@ctueck
Copy link
Member

ctueck commented Oct 13, 2022

I think there's a discrepancy between the permissions set on the actual admin API endpoints (they refer to https://www.django-rest-framework.org/api-guide/permissions/#isadminuser, which refers to is_staff in the Django user list) vs the /auth/users/me/ endpoint, which refers to is_superuser: https://github.com/EQAR/eqar_backend/blob/master/accounts/serializers.py#L23-L24

The former is correct, we agreed once that admins (= EQAR staff) are marked by the is_staff flag, whereas is_superuser is reserved for those that need actual access to DjangoSuit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant