# Hidden Group Membership

**URL:** https://meta.discourse.org/t/hidden-group-membership/62884
**Category:** Feature
**Created:** [May 15, 2017, 3:04pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884 "2017-05-15T15:04:46Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![RyanK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ryank/32/297314_2.png) [@RyanK](https://meta.discourse.org/u/RyanK)
#### Post date: [May 15, 2017, 3:04pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/1 "2017-05-15T15:04:46Z")

</div>

Any suggestions on hiding group membership, even on ones own profile page? Or leaving the names but disabling hyperlink?

---

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [May 15, 2017, 3:09pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/2 "2017-05-15T15:09:02Z")

</div>

> [@Avatar Flair (not Badges) for Groups](https://meta.discourse.org/t/avatar-flair-not-badges-for-groups/48576/64):
>
> Or leaving the names but disabling hyperlink?

You can remove the link in the title using the script from this post:  
[https://meta.discourse.org/t/apply-css-to-all-custom-non-badge-user-titles/51376/36?u=jomaxro](https://meta.discourse.org/t/apply-css-to-all-custom-non-badge-user-titles/51376/36)

---

<div class="post-metadata">

### Author: ![neil](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neil/32/102150_2.png) [@neil](https://meta.discourse.org/u/neil)
#### Post date: [May 15, 2017, 3:22pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/3 "2017-05-15T15:22:10Z")

</div>

> [@Avatar Flair (not Badges) for Groups](https://meta.discourse.org/t/avatar-flair-not-badges-for-groups/48576/56):
>
> help staff recognize customer plan level or feature adoption, and don’t want non-staff to see that info about others.

Sounds like you should use the [Staff Notes](https://github.com/discourse/discourse-staff-notes) plugin.

---

<div class="post-metadata">

### Author: ![RyanK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ryank/32/297314_2.png) [@RyanK](https://meta.discourse.org/u/RyanK)
#### Post date: [May 15, 2017, 3:23pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/4 "2017-05-15T15:23:39Z")

</div>

But we are automating group status via SSO and then potentially using group mamebership to gate select areas.

---

<div class="post-metadata">

### Author: ![RyanK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ryank/32/297314_2.png) [@RyanK](https://meta.discourse.org/u/RyanK)
#### Post date: [May 15, 2017, 5:20pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/5 "2017-05-15T17:20:46Z")

</div>

> [@Avatar Flair (not Badges) for Groups](https://meta.discourse.org/t/avatar-flair-not-badges-for-groups/48576/66):
>
> Sounds like you should use the Staff Notes plugin.

Is there a way to populate Staff Notes via SSO parameters? Or to set category permissions based on Notes?

---

<div class="post-metadata">

### Author: ![neil](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neil/32/102150_2.png) [@neil](https://meta.discourse.org/u/neil)
#### Post date: [May 17, 2017, 2:40pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/6 "2017-05-17T14:40:50Z")

</div>

No there isn’t. Staff notes isn’t going to work. We’ll need a new solution for what you’re trying to do. Maybe adding an option to groups to hide membership from all except staff.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [May 17, 2017, 2:46pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/8 "2017-05-17T14:46:09Z")

</div>

We already have the checkbox [`Group is visible to all users`] for groups.

Perhaps what we want is to change it to a drop box:

Group visibility:

- Staff only
- Group members and staff
- Everyone

In the mean time does CSS work as a workaround for hiding the groups here?

 ![](https://global.discourse-cdn.com/meta/original/3X/7/f/7f2c7961dd2e5171aff3149b6268c8dff847fe55.png)

---

<div class="post-metadata">

### Author: ![neil](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neil/32/102150_2.png) [@neil](https://meta.discourse.org/u/neil)
#### Post date: [May 17, 2017, 2:53pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/9 "2017-05-17T14:53:51Z")

</div>

We don’t have any group-specific classes on each link there.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [May 17, 2017, 2:54pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/10 "2017-05-17T14:54:28Z")

</div>

There is a trick … you target the href 🤗 in the CSS rule

---

<div class="post-metadata">

### Author: ![neil](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neil/32/102150_2.png) [@neil](https://meta.discourse.org/u/neil)
#### Post date: [May 17, 2017, 2:56pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/11 "2017-05-17T14:56:02Z")

</div>

Yeah that will work, but yuck. Don’t forget the commas!

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [May 17, 2017, 3:24pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/12 "2017-05-17T15:24:08Z")

</div>

> [@sam](#):
>
> Perhaps what we want is to change it to a drop box:
> 
> Group visibility:
> 
> Staff only  
> Group members and staff  
> Everyone

Yes this is needed. How big / risky is this change?

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [May 17, 2017, 3:25pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/13 "2017-05-17T15:25:27Z")

</div>

> [@codinghorror](#):
>
> How big / risky is this change?

not too big, probably a few hours of work, not high risk.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [May 17, 2017, 3:27pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/14 "2017-05-17T15:27:00Z")

</div>

Ok then I think we should proceed with it.

---

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [May 17, 2017, 4:15pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/15 "2017-05-17T16:15:31Z")

</div>

> [@sam](#):
>
> not too big, probably a few hours of work, not high risk.

Does this work include removing the `href` attribute from the title if the group isn’t visible to the user?

---

<div class="post-metadata">

### Author: ![RyanK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ryank/32/297314_2.png) [@RyanK](https://meta.discourse.org/u/RyanK)
#### Post date: [May 17, 2017, 5:21pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/16 "2017-05-17T17:21:56Z")

</div>

> [@codinghorror](#):
>
> I think we should proceed with it

That is great news. I will also look into the CSS solution in the interim.

Something else I’m wondering, if the group name is visible and the hyperlink is disabled, it seems like a user should be able to guess the group URL rather easily. Or even if the group name is hidden, people familiar with discourse group URLs could look around and find things.

Would it be possible to disable access to the group list view for those that do not have permission to view the group? Or would we just have to pick group names that we know…but would be difficult to guess?

Thanks for your help on this!

---

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [May 17, 2017, 5:48pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/17 "2017-05-17T17:48:27Z")

</div>

> [@RyanK](#):
>
> Would it be possible to disable access to the group list view for those that do not have permission to view the group?

Maybe I’m missing something…but isn’t that what Sam is going to be working on?

---

<div class="post-metadata">

### Author: ![RyanK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ryank/32/297314_2.png) [@RyanK](https://meta.discourse.org/u/RyanK)
#### Post date: [May 17, 2017, 6:06pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/18 "2017-05-17T18:06:36Z")

</div>

Not totally sure what that change would cover, so I wanted to cover all bases.

The setting to hide from all except staff should not only hide the group name/link from the user’s own profile, but also make sure that even a member of a group couldn’t just access the group by typing in the URL (if it was guessable or someone else shared it by mistake). But staff could still visit the user’s profile page and instantly see all groups the user is in.

That might already be what he was planning. Not sure.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [May 17, 2017, 6:07pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/19 "2017-05-17T18:07:40Z")

</div>

> [@RyanK](#):
>
> That might already be what he was planning. Not sure.

Yes that would be it, an end user would belong to a group but have no way of gleaning that information ever.

---

<div class="post-metadata">

### Author: ![RyanK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ryank/32/297314_2.png) [@RyanK](https://meta.discourse.org/u/RyanK)
#### Post date: [May 17, 2017, 6:16pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/20 "2017-05-17T18:16:03Z")

</div>

And since this is set on the group level we can choose to make some visible to members, and others totally hidden. This is probably a perfect solution for our needs.

Thanks! :content:

---

<div class="post-metadata">

### Author: ![RyanK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ryank/32/297314_2.png) [@RyanK](https://meta.discourse.org/u/RyanK)
#### Post date: [May 24, 2017, 10:04pm UTC](https://meta.discourse.org/t/hidden-group-membership/62884/21 "2017-05-24T22:04:28Z")

</div>

Is there any kind of ETA on when this might be available? Trying to determine if it’s worth a request to one of my devs to figure out the CSS tweaks.

[Next page](https://meta.discourse.org/t/hidden-group-membership/62884.md?page=2)
