Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Content managers has ability to edit global site ClientConfig settings #185

Open
NDruce opened this issue Nov 18, 2020 · 1 comment
Open
Labels

Comments

@NDruce
Copy link

NDruce commented Nov 18, 2020

Content managers has access to change values in ClientConfig, so they can, administer the site in some way. For example, access to global MODX settings is restrictable, so there is logic that ClientConfig has to be restrictable too. Please, fix access control to ClientConfig, because it can contain sensitive data that some roles of users must be denied to modify anyway and even see too.

@Mark-H
Copy link
Member

Mark-H commented Nov 18, 2020

There's #17 and #88 which request more granular permissions but I'm interested in your use case where CC contains settings that are considered sensitive.

@Mark-H Mark-H added the Feature label Nov 18, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants