Admin contre Modérateur contre Leader

Quelle est la différence entre ces 3

Leader (TL4) is the highest non-staff level one can have.

Moderator can do anything related to moderation of forum

Admin can tinker with more advanced forum settings.

In fact, admins can do everything.

:thinking: If the admin #1 (creator of the forum) put “JohnDoe” as admin… can JohnDoe remove the admin’s role to user #1 ?

Good point. The answer is no, unless John Doe also has ssh access to the server because the creator admin has her email in the app.yml which makes it unremovable via the discourse UI.

And here is another privilege of the “creator admin”:

It is actually a good question - I thought I was clear on this but am realising I can’t define it and therefore not 100% sure

I am clear about Admin vs non-admin

… but are there any practical differences between Moderator and TL4?

If you want to grant extra rights to members of your community without giving them access to the settings and the member data of the site, should you make them a Moderator, or upgrade them to TL4 instead?

TL4 is only limited to moderation of posts made by them and others.

However, moderators can do much more. Including creation of categories, viewing stats, moving posts etc.

There is very less to distinct between both but I think that /admin route is only accessible to moderators and above. Also, moderation related notifications (flags & reports) are only sent to moderators not to TL4.

I think if you give this a read it should answer a lot of questions for you

The very high level answer is that TL4s can moderate content. Mods can moderate content and users.
TL4 has no visibility of flags etc.

Merci pour cette réponse. Je connaissais beaucoup de ces principes en théorie, mais c’est seulement lorsque vous les mettez vraiment en pratique que vous remarquez les problèmes et les lacunes.

Malheureusement, cela ne répond pas à mes besoins et je ne suis pas sûr si c’est parce qu’il me manque quelque chose, ou si je dois poster quelque chose dans Contribute > Feature.

Il semble que les « Modérateurs » soient une forme d’administrateurs de rang inférieur. Je comprends que cela soit ainsi pour qu’ils puissent aider à gérer le contenu à un niveau très élevé (y compris la création de catégories, etc.) et il est donc supposé qu’ils aient également besoin d’un accès aux utilisateurs.

Cependant, dans le monde post-RGPD, en termes de sécurité des données et de confidentialité, cela pose un problème MAJEUR. Cela signifie que n’importe quel modérateur peut accéder aux zones administratives de la communauté, visiter la page des utilisateurs et télécharger la base de données principale avec des informations personnelles issues du processus SSO, y compris les noms et les adresses e-mail. Ce n’est pas acceptable.

Nous opterions donc par défaut pour transformer nos « modérateurs citoyens » en utilisateurs TL4, qui peuvent toujours modifier le contenu, mais n’ont pas accès aux utilisateurs ni ne peuvent effectuer de changements structurels. C’est correct. Cependant, cela signifie également qu’ils ne verront jamais les signalements. Bien que certains problèmes graves, tels qu’un comportement inapproprié, puissent nécessiter la vue d’un administrateur sur l’historique de l’utilisateur, ce n’est pas le cas pour les notifications concernant les liens brisés, la catégorisation incorrecte, le spam, etc.

Suis-je le seul à penser que nous avons besoin d’une solution intermédiaire, qui offre un large accès au contenu et aux signalements, mais qui restreint l’accès à toutes les données des utilisateurs ?

Existe-t-il un autre moyen d’y parvenir ?

Wait, what? As a moderator, I am not able to download the main database. I can view a user’s email address, which is then logged that I did it, but it is very much me visiting user after user after user. Can you elaborate on what you mean by “download the main database”?

if you go to the ‘user’ tab in Admin pages as a moderator, you still have access to the “export” feature. While I didn’t actually test it, I’m assuming (possibly incorrectly) that this is the same export report that I get as admin, and this includes email addresses and data in custom fields from SSO

EDIT: yes, I just re-tested it and downloaded the ‘user list’ with all the information I could want on the members while impersonating a user with ONLY moderator access, not admin level

SECOND EDIT: Looking at the logs, I also don’t see an entry for the user exporting the user list. I can see the log for my impersonation of the user, and the deletion of the PM with the export link, but no reference to the fact that the user list was exported

Oh, I see, that was not what I inferred from your original post. Now it makes sense. I’d actually be perfectly okay if that Export button wasn’t visible to Moderators, I personally never use it (as a moderator on a Discourse site). I’m not sure what moderators would be using that data for…

exactly! This would have to be hidden, and arguably we would need the option to hide custom fields in the admin version of user profiles too (as SSO carries through email).

In answer to your question, probably nothing good - and we might get into trouble with data authorities (I suspect) for not locking down access to private / personal information

@techapj just resolved the email part

I had missed that conversation - thanks

Still can’t see why the export button should be there - hopefully that will be removed too. Is this something I should cross-post there, do you think?

Je pense que la suppression de cette fonctionnalité devrait faire l’objet d’un sujet distinct, peut-être dans Contribute > Feature, avec une liste à puces expliquant pourquoi les Modérateurs n’en ont pas besoin.

Combien de modérateurs peut comporter un forum avec un plan de base ?

Pour les sites hébergés chez nous, notre formule Standard autorise jusqu’à 5 membres de l’équipe. Un membre de l’équipe est tout utilisateur qui est soit administrateur, soit modérateur, soit les deux.